canva-automation
Warn
Audited by Socket on Aug 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The capability matches Canva automation, but the skill routes OAuth-backed Canva access through a third-party intermediary and depends on a reportedly discontinued remote MCP endpoint instead of Canva's official MCP server. This is not confirmed malware, but it presents high trust and data-flow risk for an AI agent skill.
Confidence: 89%Severity: 76%
Audit Metadata