canvas-discussion-facilitator
Audited by Socket on Mar 3, 2026
1 alert found:
SecurityThe skill Fragment is PROPERLY aligned with its stated purpose as a Canvas MCP-based discussion facilitator. It uses MCP-native operations, enforces user confirmation before write actions, and provides an anonymization option for FERPA-related privacy. There are no evident malicious patterns, external download/execution vectors, or credential harvesting mechanisms. Data access is proportional to the task (course discussions, topics, posts, and user lists) and privacy controls are addressed via anonymization. Overall risk is low-to-moderate, driven primarily by potential privacy exposure if anonymization is disabled; no evidence of data exfiltration, remote control, or supply-chain abuse is present.