canvas-lms
Warn
Audited by Socket on Jul 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's stated Canvas LMS purpose is coherent and the requested Canvas credentials are proportionate, but the main risk is trust in the unseen local `canvas-lms-mcp` process that receives a live API token. No direct malicious behavior is shown, yet the core executable and credential path are insufficiently verifiable from the skill alone.
Confidence: 82%Severity: 80%
Audit Metadata