Back to skill

Security audit

canvas

Security checks for vulnerabilities and agentic risk

Overview

This skill gives Codex instructions for creating local Canvas files and includes supporting SDK type declarations, with no hidden network, credential, or install behavior found.

Install this if you want Codex to create richer Canvas artifacts for analytical outputs. Be aware it may cause Codex to write local .canvas.tsx files in Cursor's managed canvas directory and embed the source analysis data inline, so avoid using it for sensitive data you do not want stored in local artifact files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is procedural guidance about when an agent must use a canvas and when to consult the skill. The supplied code does not implement or enforce that policy. Instead, it declares types and interfaces for rendering callout tone icons in a React SDK. This is a materially different primary purpose and is unrelated to the stated canvas-usage behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes a policy/instruction skill for the agent: when to use a live React canvas in responses and when to consult the skill during .canvas.tsx work. The supplied code chunk instead is a static SDK declaration file for canvas color tokens and theme-building helpers. Its primary purpose is UI theming support, not enforcing or expressing the usage policy in the description. This is a materially different function, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is operational guidance for agent behavior: when a canvas must be used and when the skill should be consulted. The supplied code does not implement or enforce that policy. Instead, it exposes TypeScript types and React component declarations for charting primitives in a canvas environment. That is a materially different primary purpose. There is no evidence of hidden resource access or suspicious behavior, but the description does not accurately represent this code chunk’s actual function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is a policy/instructional skill about using Codex Canvas in certain response scenarios. The supplied code does not implement or support that policy in any evident way; instead, it defines the interface for a generic collapsible React component. This is a materially different primary purpose. There are no permissions or triggers involved, but the behavior of the code is unrelated to the declared description, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about a policy/instructional skill governing use of a Codex Canvas and .canvas.tsx workflows. The actual code chunk instead exposes a mathematical graph-layout API for directed acyclic graphs. It does not implement canvas rendering, canvas selection behavior, React app creation, or logic tied to analytical artifacts or MCP tool outputs. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose is an instructional skill that tells the agent when it must use a canvas and when to read the skill. The supplied code does not implement or enforce any such policy, triggers, or canvas-selection behavior. Instead, it defines React/TypeScript interfaces and exported components for displaying unified diffs and diff statistics inside a canvas SDK. While both relate broadly to canvas functionality, the primary purpose is materially different: policy guidance versus diff-view rendering primitives.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose is policy-like guidance about when an agent must use a Codex Canvas and when to read the skill. The actual code is not instructional logic, enforcement, or canvas-selection behavior; it is a .d.ts API surface for form primitives used inside canvas applications. While both relate broadly to 'canvas', the primary purpose is materially different: the description is about usage policy for canvases, while the code provides UI component declarations for building forms within canvases. That difference is substantive enough to count as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear mismatch between the declared purpose and the supplied code. The description is a behavioral instruction/policy about mandatory use of a Codex Canvas in certain response scenarios, especially for analytical artifacts and MCP tool outputs. The actual code does not implement or enforce any such policy; instead, it declares props and a React component signature for a small colored swatch used in UI decoration. This is a materially different primary purpose, not a supporting detail of the declared skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This is a clear description-behavior mismatch. The declared purpose describes behavioral guidance for an agent: when it must use a canvas, especially for analytical outputs and MCP tool results, and when to consult the skill during .canvas.tsx work. The supplied code does none of that. It is only a declaration file for theme-related exports and constants used by canvas components, such as typography, spacing, and radius tokens. While the code is related to the broader canvas ecosystem, its actual function is styling/type support, not policy enforcement or canvas-selection behavior. That makes the primary purpose materially different from the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear mismatch. The declared purpose describes a behavioral instruction/policy about using a Codex Canvas for certain kinds of responses and consulting the skill when creating or editing .canvas.tsx files. The supplied code chunk, however, is a TypeScript declaration file for todo list React components. Its primary purpose is to expose TodoList and TodoListCard props and types for rendering clickable todo items with statuses. It does not implement, enforce, or even reference canvas selection logic, analytical artifact rendering, MCP tool presentation, or .canvas.tsx workflows. The code’s actual behavior is materially different from the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose describes a policy/instructional skill about when agents must use a canvas and when to read the skill. The actual code chunk is unrelated to that purpose: it is a .d.ts declaration file for UI primitives used to build canvas interfaces. It does not encode trigger logic, enforcement, or agent behavior about choosing canvas for analytical artifacts. This is a material description-behavior mismatch because the primary purpose of the code is a component library/API definition, not a decision or guidance skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a strong mismatch between the declared description and the provided code. The description describes a substantive skill governing when and how to use a Codex Canvas, especially for analytical deliverables and .canvas.tsx workflows. The actual code is effectively a no-op declaration file with no executable logic and no relevant functionality. This is not merely incomplete supporting code; it has a materially different practical purpose from the declared skill behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose is an instructional/policy skill about when the agent should use a Codex Canvas and when to read this skill, particularly for analytical artifacts and .canvas.tsx work. The actual code chunk is only a TypeScript declaration for a segmented usage bar component used in a React canvas UI. While the component may be usable inside a canvas, it does not implement, enforce, or primarily relate to the declared policy. Its primary purpose is UI typing for a usage visualization widget, which is materially different from the declared description.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
74% confidence
Finding

The instruction that the agent 'MUST also read this skill whenever you create, edit, or debug any .canvas.tsx file' establishes a persistent trigger that can repeatedly inject this skill's guidance into future sessions and tasks. Persistent auto-loading of broad workflow instructions can bias agent behavior outside the user's immediate intent, increasing the risk of overreach, prompt-surface expansion, and inadvertent influence on unrelated file operations.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
layout. Especially prefer a canvas when presenting results from MCP tools
  (Datadog, Databricks, Linear, Sentry, Slack, etc.) where the data is the
  deliverable — render it in a rich canvas rather than dumping it into a
  markdown table or code block. If you catch yourself about to write a markdown
  table, stop and use a canvas instead. You MUST also read this skill whenever
  you create, edit, or debug any .canvas.tsx file.
metadata:

Static analysis

No suspicious patterns detected.