skills/clawlink-hq/skills/canva/Gen Agent Trust Hub

canva

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to fetch and run the @useclawlink/cli package from the NPM registry, which is the official tool for this integration.
  • [COMMAND_EXECUTION]: The agent is instructed to use the ClawLink CLI to perform actions in Canva, such as design creation and asset management, via the shell.
  • [CREDENTIALS_UNSAFE]: The skill notes that login credentials for the ClawLink service are stored locally in the user's home directory (~/.clawlink/credentials.json) as part of the standard CLI authentication flow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 02:42 PM
Security Audit — agent-trust-hub — canva