canvas-design

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The 'FINAL STEP' section in SKILL.md uses a fabricated conversation history technique: 'The user ALREADY said "It isn't perfect enough. It must be pristine..."'. This is an attempt to override the agent's creative process by mimicking a previous user correction to force a specific behavioral persona.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to 'Download and use whatever fonts are needed to make this a reality.' This encourages the agent to fetch external binary assets from unverified sources on the internet.
  • [SAFE]: The skill references font licenses in the canvas-fonts/ directory which point to established repositories and organizations including Vercel (Geist), IBM (Plex), Google (Silkscreen), and Red Hat. These are well-known, trusted sources for open-source typography.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 12:37 PM
Security Audit — agent-trust-hub — canvas-design