canvas-design

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The 'FINAL STEP' section in SKILL.md uses a technique that simulates prior user dissatisfaction by stating: 'The user ALREADY said "It isn't perfect enough. It must be pristine..."'. This is a form of instruction override that forces the model to perform additional refinement cycles regardless of the actual user input or state of the conversation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input to generate aesthetic philosophies and visual art, which represents a potential injection surface.
  • Ingestion points: User instructions are used as the foundation for 'DESIGN PHILOSOPHY CREATION' and 'CANVAS CREATION' in SKILL.md.
  • Boundary markers: None identified to separate user input from system instructions.
  • Capability inventory: Creation and writing of local files (.md, .pdf, .png).
  • Sanitization: None identified for user-provided strings interpolated into the creative process.
  • [DYNAMIC_EXECUTION]: The instructions for 'CANVAS CREATION' and refinement suggest the agent must generate and execute code (such as Python scripts using image or PDF libraries) to produce the requested visual artifacts. This is an expected behavior given the skill's primary purpose, but it constitutes a dynamic code generation pattern.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:29 AM
Security Audit — agent-trust-hub — canvas-design