morning-check

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill implements the intended functionality and aligns with expected Canvas operations, but poses moderate privacy and operational risk. Key recommendations: enforce anonymization by default or eliminate reversible local mapping files unless encrypted and access-controlled; require explicit per-action confirmation and previews before any send_conversation calls; document and enforce least-privilege OAuth scopes and secure token storage/rotation; sanitize any Canvas-originated content before embedding in messages or logs; add audit logging and retention controls. There are no clear signs of malicious code or external supply-chain execution in the provided artifact, but misconfiguration or overprivileged credentials could enable data leakage.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 3, 2026, 01:21 PM
Package URL
pkg:socket/skills-sh/vishalsachdev%2Fcanvas-mcp%2Fmorning-check%2F@0e9c6ced5a86fe4417f45d84b2e51a28ca898ab5