Agent Skill · Anthropic

Canvas design skill

Anthropic's published skill for design-quality visual output — layout, typography and composition guidance for agent-generated interfaces.

Instructions only — no bundled executables. This skill needs no credentials and no filesystem or network access beyond writing its output, which puts it at the low-risk end of the directory.

What it is, and what it costs you

This skill encodes visual judgement: spacing systems, typographic hierarchy, restraint in colour, the difference between an interface that looks designed and one that looks generated. It is a good demonstration that skills are not only for procedures — taste can be written down, and written-down taste transfers.

It is instruction text with no bundled executables and no privilege requirement, which puts it at the low-risk end of the directory alongside the artifacts skill. There is no meaningful attack surface to describe and inventing one would be dishonest.

The reason it appears in a security-oriented directory is that inventory does not only matter for dangerous artifacts. Knowing which skills are loaded is what makes the always-on context budget legible, and what makes an incident reconstructible — 'which artifacts were active in this session' is not a question you can answer selectively for the risky ones only.

The one practical caution is context cost. Design guidance is prose, prose is tokens, and a skill loaded in sessions that do not need it competes with the task for attention. That is an efficiency argument for scoping skills to the projects that use them rather than installing everything everywhere.

Capability profile

What this skill can reach inside your environment, and why a security team cares. Derived from the publisher's documentation, not from a scan.

  • instruction text only

    No executables, no credentials, no filesystem or network requirement.

  • context consumption

    Occupies context budget when loaded. An efficiency cost rather than a security risk.

Before you distribute this to a team

  • Scope to projects that need it

    Loading design guidance into unrelated sessions spends context for nothing.

  • Keep it in the inventory anyway

    Low-risk artifacts still belong in the record. Partial inventories cannot answer incident questions.

Vincosha Assay assessment

not yet assessed

We have not published a scan verdict for Canvas design skill.

Everything above is a capability profile compiled by hand from the publisher's own public documentation on 2026-07-25. It describes what this artifact can reach and what to restrict before rolling it out. It is not a security verdict, and it should not be read as one.

When Vincosha Assaypublishes an assessment for this artifact it will appear here with a verdict, the findings behind it, and the date it ran. We would rather leave this space empty than fill it with a guess — inventing a security verdict about somebody else's software would be both wrong and dangerous.

What an assessment covers

  • prompt-injection patterns in descriptions and instructions
  • credential reads and outbound egress in bundled code
  • over-scoped permissions and manifest claims
  • typosquatted and impersonating names
  • tool-manifest drift since the last approval
  • content hash against the version you approved
Scan your own artifacts with Vincosha Assay

Sources

Compiled from the publisher's own documentation and repository. Skills change — read the version you are about to install rather than trusting a profile.

Related skills

Concepts on this page

Review skills before they reach a laptop

Vincosha Assay scans skills, rules, hooks and MCP manifests at publish and on sync, and quarantines what fails. Vincosha Registry pins the version you approved so nothing changes underneath you.