canvas-component-push
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands using the
npxpackage runner to interact with the@drupal-canvas/clitool. It performs operations such ascanvas push,canvas reconcile-media, andcanvas pullto manage component and page synchronization. - [CREDENTIALS_UNSAFE]: The skill instructs the agent to verify authentication configuration within
.envfiles, shell environment variables, and the~/.canvasrcconfiguration file. These checks are limited to specific credentials (CANVAS_ACCESS_TOKEN,CANVAS_CLIENT_ID,CANVAS_CLIENT_SECRET) required for the vendor's official CLI tool.
Audit Metadata