Claude security directory
Affinity
Published by Canva
High risk
Canva's Affinity extension automates repetitive tasks in Affinity by Canva. It can render spreads or selections to images, browse and save reusable JavaScript snippets, and execute arbitrary JavaScript inside Affinity to drive the application. Because execute_script runs arbitrary JavaScript in the Affinity process, the extension can do anything the Affinity scripting environment allows - including reading and modifying the open document.
Security assessment
Plutonium assessed this desktop extension for permissions, capabilities, and security-relevant behavior.
- Can run commands or queries on your behalf: This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.
- Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
Available capabilities
This add-on exposes 11 tools or capabilities.
- execute_script
- render_spread
- render_selection
- list_sdk_documentation
- read_sdk_documentation_topic
- search_sdk_hints
- list_library_scripts
- read_library_script
- save_script_to_library
- add_sdk_hint
- report_sdk_issue
The interactive security report will load automatically.