canvas-design

Warn

Audited by Gen Agent Trust Hub on Mar 1, 2026

Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill's 'FINAL STEP' section utilizes a deceptive 'simulated history' technique by stating 'The user ALREADY said...' to force the agent into a specific refinement loop, overriding the actual interaction history and forcing a subjective 'perfection' state regardless of real input.\n- [EXTERNAL_DOWNLOADS]: The 'CANVAS CREATION' section includes an explicit instruction to 'Download and use whatever fonts are needed', which triggers network requests to fetch assets from unspecified and potentially untrusted external domains.\n- [NO_CODE]: No executable scripts, Python modules, or binary files were found within the skill package; it consists solely of markdown instructions, Apache license text, and multiple SIL Open Font License documentation files.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 1, 2026, 01:33 AM