Back to skill

Security audit

Canvas Json Handler

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local canvas-file automation helper, and its file-changing behavior fits its stated purpose.

Install this only if you want an agent to create and modify local .canvas files. Use snapshots or version control before large merges, repair runs, rollback operations, or aggressive repair mode, and review previews for important canvases.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill advertises merge, rollback, batch processing, and repair capabilities that can create, overwrite, or materially alter canvas files, but it does not provide an explicit up-front warning that these are state-changing operations. In an agent context with `exec` enabled, lack of clear user confirmation boundaries increases the chance of unintended destructive actions or silent modification of project data.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The intelligent repair engine is described as automatically rebuilding fields, remapping IDs, redistributing coordinates, and potentially deleting dangling edges, but the documentation does not clearly warn users that data may be altered or removed. This is risky because users may invoke 'repair' expecting validation only, while the agent may perform irreversible or hard-to-audit modifications to canvas structure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.