studioai-canvas
Warn
Audited by Socket on May 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s actions are largely coherent with its stated canvas-management purpose, and no clear exfiltration or credential harvesting is shown. However, it requires an unverified studioai-mcp server with persistent write capabilities, so the main concern is install/execution trust and the ability to overwrite project data through a black-box dependency.
Confidence: 83%Severity: 72%
Audit Metadata