canva-automation
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s Canva automation purpose is coherent, but it relies on an intermediary MCP service that appears deprecated and routes Canva authorization/data through a third party rather than Canva’s official MCP. This is not confirmed malware, but the outdated hosted dependency and indirect data flow create medium security risk.
Confidence: 87%Severity: 58%
Audit Metadata