canvas

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No clear signs of embedded malware or intentional data-exfiltration code are present in the provided documentation. The Canvas feature is powerful and by design allows arbitrary web content to be executed on connected devices; this creates a moderate-to-high operational security risk if the host, bridge, operator account, or network are compromised. Key mitigations missing from the documentation include authentication/TLS for the HTTP server and bridge, authorization/consent on nodes for actions (especially eval), guidance to avoid placing sensitive files in the canvas root, and recommendations for logging and access controls. Treat the package as functional but requiring hardening before deployment in untrusted networks.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 28, 2026, 07:25 AM
Package URL
pkg:socket/skills-sh/TermiX-official%2Fcryptoclaw%2Fcanvas%2F@c25bec2def998abf2312de8c3ea8fb1acc8efb39