canvas-design

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The 'FINAL STEP' section of the instructions pre-loads behavioral constraints by claiming the user has already expressed that the work is not perfect enough, effectively overriding the agent's perception of the actual user's intent to force a refinement loop.\n- [EXTERNAL_DOWNLOADS]: The skill explicitly instructs the agent to 'Download and use whatever fonts are needed' to create the artwork, which facilitates the fetching of external files from unverified third-party sources without integrity validation or source restrictions.\n- [PROMPT_INJECTION]: The skill ingests user input to generate design philosophies and canvas outputs without providing explicit boundary markers or sanitization procedures. The agent possesses file-writing and network download capabilities while processing this untrusted data (ingestion via the original request and subtle input), creating a surface for indirect prompt injection if the user input contains embedded instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:10 AM