Back to skill

Security audit

Canva

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Canva connector that uses OOMOL's CLI and account connection to read and update Canva resources, with no malicious indicators found.

Install this only if you are comfortable connecting Canva through OOMOL and letting the agent perform Canva actions through the `oo` CLI. Review write payloads before approval, especially create, upload, export, and move operations, and only run the CLI installer or login flow when you intentionally want to set up OOMOL access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.