canvas-a2ui

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is conceptually benign for programmatic diagram/chart/image generation and its capabilities match its stated purpose. However, several legitimate features carry meaningful security risk if misconfigured: canvas_eval allows arbitrary JS execution in the browser context, canvas_image can cause reads of arbitrary local files, and the optional local server creates an exposed surface. The documentation's note permitting network access "unless explicitly allowed" is a notable risk because enabling network access would permit easy exfiltration of canvas contents or files rendered to canvas. Overall the skill is not demonstrably malicious based on the provided documentation, but it is potentially exploitable and should be treated as suspicious unless deployed with strict sandboxing, read/write restrictions, and network controls.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:13 AM
Package URL
pkg:socket/skills-sh/winsorllc%2Fupgraded-carnival%2Fcanvas-a2ui%2F@e25a1f9d4c6435c9ab6e16a807cd946947b7d13d