Canva Automation
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill bundle is designed for automating Canva tasks via the Rube MCP. It instructs the agent to connect to an external MCP server at `https://rube.app/mcp` and utilize various Canva-related tools. While the skill enables the agent to perform actions like fetching assets from arbitrary URLs for upload (via `CANVA_CREATE_ASSET_UPLOAD_JOB` in SKILL.md), these capabilities are aligned with the stated purpose of Canva automation. There is no evidence of intentional harmful behavior, prompt injection attempts to subvert the agent, or other malicious instructions within the provided files. The risks are primarily related to the inherent capabilities of the tools and the supply chain dependency on the external Rube MCP, rather than malicious intent in the skill itself.
