canvas-design

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The 'FINAL STEP' section uses a technique to simulate past user feedback ('The user ALREADY said...') to force the model into a specific high-effort state. This is a form of behavioral manipulation designed to bypass the model's standard response patterns.\n- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to 'Download and use whatever fonts are needed,' which encourages network activity to potentially unverified external sources to retrieve binary font files without specifying trusted domains.\n- [COMMAND_EXECUTION]: The prompt directs the agent to search local directories ('./canvas-fonts') and implies iterative code execution ('Go back to the code and refine') to generate visual artifacts, requiring significant file system and runtime capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 04:37 AM