Back to skill

Security audit

canvas-design

Security checks for vulnerabilities and agentic risk

Overview

This skill mixes a canvas-design pitch with broad development automation, shell execution, API credentials, and administrator guidance that are not well scoped for static design work.

Review carefully before installing. Treat this as a broad automation skill, not just a design helper; only use it in a sandboxed workspace, do not provide API keys or credentials unless you know exactly what service is being called, and do not run it with administrator privileges.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:16
Finding

Unrestricted Execution Capability Exceeds the Skill's Stated Requirements

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest advertises a benign visual art/poster design skill, but the declared tools and surrounding documentation introduce generic development automation and command-execution behavior. This mismatch is dangerous because it can cause the agent or user to trust and invoke a skill under false pretenses, enabling broader system interaction than expected.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation description is broad, mixed-language, and spans unrelated domains, making accidental invocation for inappropriate tasks more likely. When a skill also exposes read/exec tools, overly permissive routing can trigger higher-risk behavior in contexts where the user only expected harmless content creation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The core-function section contradicts the skill's stated purpose by describing development automation, structured data processing, retries, and batch workflows instead of art generation. In an agent ecosystem, this kind of capability confusion is dangerous because policy, invocation, and user consent may be based on the claimed low-risk design role rather than the actual higher-risk automation behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

A skill presented as static visual design should not unexpectedly request API keys, establish external connections, or execute commands without very clear justification and warning. These undocumented operational capabilities expand the attack surface and can lead to credential exposure, unintended network access, or filesystem changes during what appears to be a low-risk design task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage guidance references API-key configuration, API calls, file preparation, and command execution, but the skill does not clearly warn users up front that it may affect the local system, external services, or sensitive credentials. This lack of informed consent is risky because users may invoke what looks like a design tool without realizing it can execute commands or handle secrets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.