canva-automation

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions define standard workflows for design automation and asset management using the Canva API. All described behaviors are consistent with the skill's stated design purpose.
  • [EXTERNAL_DOWNLOADS]: The skill references the Rube MCP endpoint (https://rube.app/mcp) and toolkit documentation on composio.dev. These represent the necessary infrastructure and official resources for the service being integrated.
  • [DATA_EXFILTRATION]: Includes tools such as CANVA_CREATE_ASSET_UPLOAD_JOB which takes a url parameter. This is a standard feature for uploading remote files to Canva and does not indicate malicious data exfiltration.
  • [COMMAND_EXECUTION]: The skill uses structured MCP tool calls to perform operations. It does not attempt to execute arbitrary shell commands or access sensitive system files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 04:24 PM
Security Audit — agent-trust-hub — canva-automation