skills/zoom/skills/zoom-mcp/canvas/Gen Agent Trust Hub

zoom-mcp/canvas

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides tools that read content from Zoom Canvas documents, which creates a surface where embedded malicious instructions could influence agent behavior.
  • Ingestion points: External data is retrieved via tools such as get_file_content as described in references/tools.md.
  • Boundary markers: There are no instructions for using delimiters or boundary markers to isolate ingested content from agent instructions.
  • Capability inventory: The skill allows the agent to perform administrative and destructive actions such as canvas_delete_file, canvas_delete_block, canvas_remove_file_collaborator, and canvas_transfer_file_ownership.
  • Sanitization: The skill does not implement or describe content validation or sanitization for the data retrieved from the Zoom Canvas API.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 09:55 PM
Security Audit — agent-trust-hub — zoom-mcp/canvas