canvas
Pass
Audited by Gen Agent Trust Hub on Apr 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's core functionality is to generate visual representations of system architecture, code structure, and user journeys. All analyzed files focus on providing templates and logic for these legitimate development tasks.
- [DATA_EXFILTRATION]: While the skill is designed to read project source code, database schemas, and API definitions to generate diagrams, there are no instructions to transmit this data to unauthorized external endpoints. References to external services like Kroki or draw.io are consistent with industry-standard diagram rendering workflows.
- [EXTERNAL_DOWNLOADS]: The skill mentions several static analysis helpers such as pyan, PyCG, and code2flow. These are documented as optional tools for the agent to use when performing reverse-engineering and do not involve hidden or malicious download scripts.
- [PROMPT_INJECTION]: The instructions do not contain attempts to bypass AI safety filters or override agent behavior. The use of instructional directives like 'Never' and 'Always' is strictly bound to maintaining diagram syntax, readability, and accessibility compliance (e.g., WCAG 2.2).
- [COMMAND_EXECUTION]: The skill defines workflows for generating diagram code but does not include any commands for arbitrary shell execution, privilege escalation, or persistence on the host system.
Audit Metadata