canvas-component-push

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands using the npx package runner to interact with the @drupal-canvas/cli tool. It performs operations such as canvas push, canvas reconcile-media, and canvas pull to manage component and page synchronization.
  • [CREDENTIALS_UNSAFE]: The skill instructs the agent to verify authentication configuration within .env files, shell environment variables, and the ~/.canvasrc configuration file. These checks are limited to specific credentials (CANVAS_ACCESS_TOKEN, CANVAS_CLIENT_ID, CANVAS_CLIENT_SECRET) required for the vendor's official CLI tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 09:30 PM