Security audit
Canva
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed Canva connector that uses OOMOL's CLI and account connection to read and update Canva resources, with no malicious indicators found.
Install this only if you are comfortable connecting Canva through OOMOL and letting the agent perform Canva actions through the `oo` CLI. Review write payloads before approval, especially create, upload, export, and move operations, and only run the CLI installer or login flow when you intentionally want to set up OOMOL access.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
