canvas-component-upload

Pass

Audited by Gen Agent Trust Hub on Feb 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • COMMAND_EXECUTION (SAFE): The skill uses npx to execute deployment commands (canvas upload). This behavior is consistent with the skill's primary purpose and is protected by a human-in-the-loop confirmation step.\n- EXTERNAL_DOWNLOADS (SAFE): The skill references the @drupal-canvas/cli npm package and provides links to official Drupal project documentation. These are reputable sources for the specified task.\n- PROMPT_INJECTION (SAFE): No malicious instructions, bypass attempts, or extraction patterns were identified within the skill's body or metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 18, 2026, 10:21 PM