canvas-course-audit

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from an external Canvas LMS course during the audit process.
  • Ingestion points: The skill fetches metadata, syllabus, module structure, assignment rubrics, discussion topics, and page content via the canvas-mcp server (SKILL.md).
  • Boundary markers: The audit workflow does not specify the use of delimiters or instructions for the agent to ignore potentially malicious instructions embedded within the course content.
  • Capability inventory: The skill retrieves comprehensive course data and generates structured reports but does not demonstrate high-privilege write operations or external network exfiltration outside the MCP environment.
  • Sanitization: No evidence of input sanitization or filtering of course content is described in the provided workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 06:32 PM