canvas-course-audit
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from an external Canvas LMS course during the audit process.
- Ingestion points: The skill fetches metadata, syllabus, module structure, assignment rubrics, discussion topics, and page content via the canvas-mcp server (SKILL.md).
- Boundary markers: The audit workflow does not specify the use of delimiters or instructions for the agent to ignore potentially malicious instructions embedded within the course content.
- Capability inventory: The skill retrieves comprehensive course data and generates structured reports but does not demonstrate high-privilege write operations or external network exfiltration outside the MCP environment.
- Sanitization: No evidence of input sanitization or filtering of course content is described in the provided workflow.
Audit Metadata