canvas-discussion-facilitator

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-generated content from LMS discussion forums and has write permissions, establishing an indirect prompt injection surface.
  • Ingestion points: Discussion post bodies and replies are ingested through the list_discussion_entries and get_discussion_entry_details tools as described in SKILL.md.
  • Boundary markers: No structural prompt encapsulation or formatting boundaries are specified to keep data separate from instructions.
  • Capability inventory: The skill possesses powerful write capabilities, including reply_to_discussion_entry, post_discussion_entry, create_discussion_topic, create_announcement, and send_conversation tools.
  • Sanitization: External content is not sanitized or validated before presentation, although the risk is partially mitigated by mandatory user confirmation steps prior to executing write tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:06 PM
Security Audit — agent-trust-hub — canvas-discussion-facilitator