canvas-design-decomposition
Pass
Audited by Gen Agent Trust Hub on Apr 26, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses instructional language such as 'Mandatory triggers' and 'Do not skip' to ensure agent reliability and adherence to the workflow. These are standard behavioral guidelines and do not attempt to bypass safety filters or extract system prompts.
- [DATA_EXFILTRATION]: No evidence of unauthorized data access or exfiltration. The skill references external URLs like Figma for design input and mentions an internal tool for URL scraping, which are within the scope of its documented purpose as a design decomposition tool.
- [REMOTE_CODE_EXECUTION]: The skill does not contain commands to download or execute external scripts. It relies on internal relative references to other skills within the same environment to maintain workflow continuity.
- [COMMAND_EXECUTION]: No dangerous shell commands or privilege escalation attempts were found. The workflow output is restricted to generating Markdown templates for human review.
- [SAFE]: The skill follows security best practices by focusing on a planning and modeling phase before any implementation occurs, and it does not handle sensitive credentials or private environment variables.
Audit Metadata