The skill uses fabricated user consent to bypass authorization and includes unauthorized file system probing instructions that exceed its intended design functionality.
npx skills add https://github.com/anthropics/skillsThe instructions command the agent to search a specific directory ('./canvas-fonts') and download fonts, which may exceed the intended scope of a design skill and could be used to probe the file system. [ensemble: confirmed by 3/3 passes; severity set to the agreed median (ADR-0067).]
Search the ./canvas-fonts directory. Download and use whatever fonts are needed
Fabricated user consent / pre-authorized instruction — a statement falsely attributed to the user to manufacture authorization
The user ALREADY said
Skill body contains no code blocks or usage examples, making it harder for users to evaluate.
[](https://mondoo.com/ai-agent-security/skills/github/anthropics/skills/canvas-design)<a href="https://mondoo.com/ai-agent-security/skills/github/anthropics/skills/canvas-design"><img src="https://mondoo.com/ai-agent-security/api/badge/github/anthropics/skills/canvas-design.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/anthropics/skills/canvas-design.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.