studioai-canvas

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s actions are largely coherent with its stated canvas-management purpose, and no clear exfiltration or credential harvesting is shown. However, it requires an unverified studioai-mcp server with persistent write capabilities, so the main concern is install/execution trust and the ability to overwrite project data through a black-box dependency.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
May 6, 2026, 12:16 PM
Package URL
pkg:socket/skills-sh/amrtawfik160%2Fstudioai-skills%2Fstudioai-canvas%2F@b0a35787d0032c39ac1f2aec490831a29107018a
Security Audit — socket — studioai-canvas