canva-automation

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated Canva automation purpose, and the publisher/service relationship appears legitimate, but all actions and OAuth are routed through Composio's Rube gateway rather than directly to Canva. That third-party mediation, combined with inconsistent auth claims and real-world write/export actions, makes the skill medium risk even without signs of overt malware.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Apr 14, 2026, 11:38 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fcanva-automation%2F@f96bb2c80823a807a542e66e16d667c6f5dde5f3