canvas-data-fetching

Warn

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a complex shell command using node -e to execute a multi-line JavaScript block. This is used as a development probe to inspect the data shape of a Drupal JSON:API endpoint by importing the drupal-canvas and drupal-jsonapi-params packages.
  • [CREDENTIALS_UNSAFE]: The instructions direct the agent to resolve site configuration by reading the .env file in the project root and the ~/.canvasrc file in the user's home directory. Reading these configuration files can expose environment-specific details and potentially sensitive credentials.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 24, 2026, 11:57 AM