canva-automation

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s Canva capabilities are broadly aligned with its stated purpose, and there is no malware-like installer or exploit behavior. However, the setup instructions are materially inconsistent with official docs about required credentials, and all user data and actions are routed through a third-party MCP/Composio broker rather than directly to Canva. That intermediary design is plausible for this ecosystem but adds medium risk around credential forwarding and data flow integrity.

Confidence: 90%Severity: 66%
Audit Metadata
Analyzed At
Mar 13, 2026, 07:00 AM
Package URL
pkg:socket/skills-sh/aAAaqwq%2FAGI-Super-Team%2Fcanva-automation%2F@bf1caf30b4ed6d39b6d625392b9fcd85e3c0dd08