@iflow-mcp/mattcoatsworth-canva-mcp-server
Unknown developer
Threat Summary
Key Security Threats
YARA rule match: -postinstall_file_manipulation
/tmp/extract-bbd817342138661ddd3b37ad5dc6b3b64fdbc188aa3060aa601dac173b5da192-3912018426/src/resources.js
MCP transport security issue: HARDCODED-TOKEN-.env
.env
YARA rule match: -credential_env_files
/tmp/extract-bbd817342138661ddd3b37ad5dc6b3b64fdbc188aa3060aa601dac173b5da192-3912018426/src/api-client.js
YARA rule match: -postinstall_environment_access
/tmp/extract-bbd817342138661ddd3b37ad5dc6b3b64fdbc188aa3060aa601dac173b5da192-3912018426/src/api-client.js
YARA rule match: -credential_env_files
/tmp/extract-bbd817342138661ddd3b37ad5dc6b3b64fdbc188aa3060aa601dac173b5da192-3912018426/README.md
All Findings (38)
View all 38 security findings
YARA rule match: -postinstall_file_manipulation
MCP transport security issue: HARDCODED-TOKEN-.env
YARA rule match: -credential_env_files
YARA rule match: -postinstall_environment_access
YARA rule match: -credential_env_files
YARA rule match: -postinstall_network_communication
XIOC detected Domain: asset.id
XIOC detected Domain: brand.name
XIOC detected URL: https://example.com/thumbnail.jpg',
XIOC detected URL: https://example.com/asset.jpg'
XIOC detected URL: https://www.canva.dev/
XIOC detected URL: https://www.canva.com/design/$
XIOC detected Domain: brand.id
XIOC detected URL: https://api.canva.com/v1';
XIOC detected Domain: color.name
XIOC detected Domain: brand.fonts.map
XIOC detected Domain: font.name
XIOC detected Domain: github.com
XIOC detected URL: https://github.com/iflow-mcp/mattcoatsworth-canva-mcp-server
XIOC detected Domain: api.canva.com
XIOC detected Domain: response.data
XIOC detected Domain: error.response.data
XIOC detected Domain: www.canva.dev
XIOC detected Domain: www.canva.com
XIOC detected Domain: design.id
XIOC detected Domain: brand.colors.map
HASH-77afa981e946f616
HASH-cd0e05b90dd41c07
HASH-00c1212e99cf7b4a
HASH-b292c1e66aea5b22
HASH-58557d09097b90ae
HASH-d54d7f4c7766fc07
HASH-1911973a7dfc3f60
HASH-39e7b2558ada07dc
HASH-94fa02a7b9930bdc
HASH-63d1615721de36e1
HASH-de46fe1c58ead693
HASH-1fdb92e54b591404
Recommended Action
This extension has significant security concerns that warrant careful review. Consider uninstalling or finding a safer alternative. If you must use it, limit the permissions and monitor for suspicious activity.