Agent skill

Canva Policy Guardrails

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Implement repository and runtime controls for Canva Connect authorization, secrets, previews, data, retries, and CI trust.

MITAuto-check passedAI & LLM Engineering

Install Canva Policy Guardrails

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-policy-guardrails -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace canva-policy-guardrails --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/canva-policy-guardrails .claude/skills/canva-policy-guardrails && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
canva-policy-guardrails
GitHub stars
2.8k
Token cost
~975 tokens
SKILL.md length
403 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Implement repository and runtime controls for Canva Connect authorization, secrets, previews, data, retries, and CI trust.

  • Works in 7 steps: Classify controls → Add secret controls → Add authorization controls → …
  • Converting integration policy into testable deny-by-default checks
  • SKILL.md covers Overview, Prerequisites, Instructions and Authentication, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Canva Policy Guardrails is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement repository and runtime controls for Canva Connect authorization, secrets, previews, data, retries, and CI trust. Use when converting integration policy into testable deny-by-default checks. Trigger with: "add Canva guardrails", "lint Canva integration", "enforce Canva policy".

Its SKILL.md is about 980 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Requires an approved policy owner, repository scope, exception process, and current Canva contracts.

It sits in AI & LLM Engineering, covering LLM guardrails and Authorization and RBAC. It works with Canva. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Converting integration policy into testable deny-by-default checks
  • With: add Canva guardrails
  • Lint Canva integration
  • Enforce Canva policy

Example prompts

  • “add Canva guardrails”
  • “lint Canva integration”
  • “enforce Canva policy”
  • “/canva-policy-guardrails”

Requirements

  • Compatibility (from SKILL.md): Requires an approved policy owner, repository scope, exception process, and current Canva contracts.
  • Pre-approved tools (allowed-tools): Read, Grep, Write, Edit

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Classify controls
  2. Add secret controls
  3. Add authorization controls
  4. Add operation controls
  5. Add contract controls
  6. Add evidence controls
  7. Govern exceptions

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • canva.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires an approved policy owner, repository scope, exception process, and current Canva contracts.

    From compatibility in the SKILL.md frontmatter.

Context cost

Canva Policy Guardrails loads about 975 tokens when it runs, and up to ~1.1k if it reads all its reference files. Until then it costs about 78 tokens; SKILL.md has 403 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~975
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 403 words, ~975 tokens.

Download SKILL.mdSave it as .claude/skills/canva-policy-guardrails/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
canva-policy-guardrails
description
Implement repository and runtime controls for Canva Connect authorization, secrets, previews, data, retries, and CI trust. Use when converting integration policy into testable deny-by-default checks. Trigger with: "add Canva guardrails", "lint Canva integration", "enforce Canva policy".
allowed-tools
Read, Grep, Write, Edit
compatibility
Requires an approved policy owner, repository scope, exception process, and current Canva contracts.
version
2.0.0
argument-hint
[repository-path-and-policy-profile]
model
inherit
effort
high
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, canva, policy, operations

Canva Integration Policy Guardrails

Overview

Encode high-confidence invariants close to the code and verify them again at runtime. Keep provider-dependent facts versioned so a stale numeric limit or preview assumption cannot become permanent policy.

Prerequisites

  • Policy document, owner, enforcement scope, and exception expiry
  • Repository/runtime boundaries and pinned provider contract
  • Current secret, scope, data, CI-event, and preview inventory

Instructions

Step 1: Classify controls

Separate immutable security controls from versioned provider-contract checks and local operational thresholds. Name the authority for each.

Step 2: Add secret controls

Use Write or Edit to block client secrets/tokens in source, frontend bundles, logs, snapshots, artifacts, and untrusted CI; scan examples and failure paths too.

Step 3: Add authorization controls

Require tenant/resource ownership, application policy, explicit minimum scopes, current capabilities, and preview status before dispatch.

Step 4: Add operation controls

Require operation identity for mutations, bounded retry classification, async job reconciliation, and scoped queues for throttling.

Step 5: Add contract controls

Pin OpenAPI or checksum, test unknown fields/statuses safely, detect deprecated/preview surface drift, and require review before regeneration.

Step 6: Add evidence controls

Use Read and Grep to verify each rule fires on a failing fixture, cannot be bypassed by formatting, and produces a redacted reason with owner and exception path.

Step 7: Govern exceptions

Make exceptions narrow, approved, time-bounded, visible in CI, and automatically fail after expiry.

Show full SKILL.md (182 more words)Show less

Authentication

Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.

Tool Discipline

Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.

Output

  • Scoped decision or implementation artifact
  • Redacted operation and validation receipt
  • Failure, rollback, and follow-up ownership record

Examples

A CI rule rejects Canva client secrets in browser configuration and privileged live tests on fork events; a runtime guard separately denies a design write without tenant ownership and explicit scope.

Error Handling

FailureResponse
Rule depends on stale numeric limitMove the value to a versioned contract fixture
Exception has no expiryReject it
Guard logs protected inputReturn only a stable reason code
Static rule cannot prove runtime ownershipAdd a runtime deny-by-default check

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/canva-policy-guardrails of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Canva Policy Guardrails next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Canva Policy Guardrails compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Canva Policy Guardrails this skilljeremylongshore/tons-of-skills-marketplace2.8k—~975Automated safety check: PassMIT
Writing Eval Scenariosopen-bias/open-bias143—~1.5kAutomated safety check: PassApache-2.0
Tool Permission System Designsimbajigege/book2skills183—~2.1kAutomated safety check: PassApache-2.0
New Policy Engineopen-bias/open-bias143—~1.3kAutomated safety check: PassApache-2.0
Aisafetyhotwuyoscar/AISafetyHot-Hub827—~1.4kAutomated safety check: PassCustom licence
ObliteratusRedWoodOG/Hermes-Desktop1775 repos~3.8kAutomated safety check: PassMIT

Similar skills

  • Writing Eval Scenarios

    open-bias/open-bias

    Guide for writing eval conversation JSONs and running them through policy engines

    143 GitHub stars~1.5k tokensUpdated 4 days ago
    AI & LLM EngineeringAuto-check passed
  • Tool Permission System Design

    simbajigege/book2skills

    Guides designing a layered permission pipeline for agent tools that decides which calls are allowed, need confirmation or are denied, with scopes and hooks.

    183 GitHub stars~2.1k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed
  • New Policy Engine

    open-bias/open-bias

    Guide for creating a new policy engine under openbias/policy/engines/

    143 GitHub stars~1.3k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Aisafetyhot

    wuyoscar/AISafetyHot-Hub

    Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service.

    827 GitHub stars~1.4k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Obliteratus

    RedWoodOG/Hermes-Desktop

    Remove refusal behaviors from open-weight LLMs using OBLITERATUS — mechanistic interpretability techniques (diff-in-means, SVD, whitened SVD, LEACE, SAE decomposition, etc.) to excise guardrails…

    177 GitHub starsUsed in 5 repos~3.8k tokens
    AI & LLM EngineeringAuto-check passed
  • Turns a natural-language description of routing intent into a valid Lemonade collection.router policy JSON.

    408 GitHub stars~4k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Canva Policy Guardrails

What does Canva Policy Guardrails do?

Implement repository and runtime controls for Canva Connect authorization, secrets, previews, data, retries, and CI trust. Canva Policy Guardrails is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement repository and runtime controls for Canva Connect authorization, secrets, previews, data, retries, and CI trust.

When should I use Canva Policy Guardrails?

Canva Policy Guardrails fits situations like: converting integration policy into testable deny-by-default checks; with: add Canva guardrails; lint Canva integration; enforce Canva policy.

How do I install Canva Policy Guardrails in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-policy-guardrails -a claude-code`. Or copy the skill folder (skills/.curated/canva-policy-guardrails in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/canva-policy-guardrails in your project. Claude Code loads it when a task matches its description.

How do I install Canva Policy Guardrails in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-policy-guardrails -a codex`. Or copy the skill folder (skills/.curated/canva-policy-guardrails in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/canva-policy-guardrails in your project. Codex loads it when a task matches its description.

Can I use Canva Policy Guardrails in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-policy-guardrails -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/canva-policy-guardrails, .gemini/skills/canva-policy-guardrails, .github/skills/canva-policy-guardrails and .opencode/skills/canva-policy-guardrails in your project.

What does Canva Policy Guardrails need to run?

SKILL.md names no scripts, command-line tools or credentials: Canva Policy Guardrails is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Write, Edit. Compatibility (from SKILL.md): Requires an approved policy owner, repository scope, exception process, and current Canva contracts..

Does Canva Policy Guardrails access the network?

SKILL.md names 1 domain. As links in the text: canva.dev. This is read from the text; nothing was executed.

Is Canva Policy Guardrails safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Canva Policy Guardrails use?

Canva Policy Guardrails is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Canva Policy Guardrails use?

About 975 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 124 tokens, read only when the agent opens those files.

What are the alternatives to Canva Policy Guardrails?

Skills that share tags, products or a category with Canva Policy Guardrails: Writing Eval Scenarios (open-bias/open-bias, 143 stars), Tool Permission System Design (simbajigege/book2skills, 183 stars), New Policy Engine (open-bias/open-bias, 143 stars) and Aisafetyhot (wuyoscar/AISafetyHot-Hub, 827 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Canva Policy Guardrails?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.