{"generated_at":"2026-08-17T10:36:11+00:00","item":{"added_at":"2026-04-16T15:48:14.328000+00:00","analysis_method":"capability_triage","category":"Desktop Extension","description":"Automate Affinity tasks via Claude - render selections, manage script libraries, and execute arbitrary JavaScript in the Affinity process.","did":"ant-dir-gh-canva-affinity","homepage_url":"https://affinity.studio","icon":"https://claude.ai/api/dxt/extensions/ant.dir.gh.canva.affinity/versions/1.0.8/icon.png","id":"ant.dir.gh.canva.affinity","installs":9457,"last_scanned":"","license":"","long_description":"Canva's Affinity extension automates repetitive tasks in Affinity by Canva. It can render spreads or selections to images, browse and save reusable JavaScript snippets, and execute arbitrary JavaScript inside Affinity to drive the application.\n\nBecause execute_script runs arbitrary JavaScript in the Affinity process, the extension can do anything the Affinity scripting environment allows - including reading and modifying the open document.","name":"Affinity","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=ant-dir-gh-canva-affinity&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"Canva","publisher_url":"https://affinity.studio","repository_url":"","risk":"high","risk_severity":"high","security_risks":[{"description":"This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.","evidence":"1 code execution tools on this connector - e.g. execute_script.","remediation":{"block_tool_categories":["code_execution"],"steps":["In the tools list below, turn off any tool tagged Block before connecting this to real data or production systems.","If you need code execution, run it on a separate test machine that has no access to your work files, customer data, or saved passwords.","Limit which websites and services that test machine can talk to."]},"risk_type":"runs_code","severity":"high","title":"Can run commands or queries on your behalf"},{"description":"This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.","evidence":"2 state change tools on this connector - e.g. save_script_to_library, add_sdk_hint.","remediation":{"block_tool_categories":["state_change"],"steps":["Try the connector on a test account first to see what it changes before letting it touch your real records.","Where the connected service supports it, give Claude read-only access and only allow writes for the specific things you need updated.","In the tools list below, turn off any tool you don't actively need - the ones tagged Block are the most important to disable."]},"risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"},{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Connector has 11 tools; permissions on claude.ai/directory: \"Local\". Data flows out of the connected service into the model.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"low","title":"Reads your private information"}],"signature_status":"unsigned","source_code_reviewed":false,"tags":["desktop_extension","creative_tools","runs_code"],"tools":[{"description":"Execute Javascript and return the results.","name":"execute_script","risk":{"category":"code_execution","level":"high","recommendation":"Block by default. Only enable in a sandboxed environment that can't reach production data or credentials.","why":"Runs scripts, commands, or queries the model authors. A malicious prompt can use this to run arbitrary code on the host, read files, or pivot to other systems."}},{"description":"Render a spread to a base64 encoded JPEG.","name":"render_spread"},{"description":"Render the currently selected nodes to a base64 encoded JPEG.","name":"render_selection"},{"description":"List the available SDK documentation topics.","name":"list_sdk_documentation"},{"description":"Read an SDK documentation topic","name":"read_sdk_documentation_topic"},{"description":"Search a global pool of SDK hints from millions of other MCP sessions.","name":"search_sdk_hints"},{"description":"List the names of the scripts in the script library.","name":"list_library_scripts"},{"description":"Read a script from the script library.","name":"read_library_script"},{"description":"Save a script to the script library.","name":"save_script_to_library","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Add a hint so future sessions can be more efficient.","name":"add_sdk_hint","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Report an issue with the SDK to the Affinity.","name":"report_sdk_issue"}],"tools_count":11,"type":"desktop_extension","url":"","uuid":"cc165410-d5af-5fe3-ba46-d002f22b23bd","version":"1.0.8"},"query_key":"canva affinity","schema_version":1,"status":"match"}
