Agent skill

Canva Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Implement the Canva Connect security baseline for backend OAuth, least privilege, tenant isolation, logging, revocation, and preview webhook verification.

MITAuto-check passedBackend & APIs

Install Canva Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace canva-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/canva-security-basics .claude/skills/canva-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
canva-security-basics
GitHub stars
2.8k
Token cost
~1.1k tokens
SKILL.md length
433 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Implement the Canva Connect security baseline for backend OAuth, least privilege, tenant isolation, logging, revocation, and preview webhook verification.

  • Works in 7 steps: Inventory secrets and flows → Harden OAuth → Minimize authorization → …
  • Threat-modeling
  • SKILL.md covers Overview, Prerequisites, Instructions and Authentication, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Canva Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement the Canva Connect security baseline for backend OAuth, least privilege, tenant isolation, logging, revocation, and preview webhook verification. Use when threat-modeling, reviewing, or hardening an integration. Trigger with: "secure Canva integration", "Canva token security", "verify Canva webhook".

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Requires a backend web application, approved secret store, threat owner, and current Canva security documentation.

It sits in Backend & APIs, covering Webhooks, OAuth and OpenID Connect and Multi-tenancy. It works with Canva. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Threat-modeling
  • Hardening an integration
  • With: secure Canva integration
  • Canva token security

Example prompts

  • “secure Canva integration”
  • “Canva token security”
  • “verify Canva webhook”
  • “/canva-security-basics”

Requirements

  • Compatibility (from SKILL.md): Requires a backend web application, approved secret store, threat owner, and current Canva security documentation.
  • Pre-approved tools (allowed-tools): Read, Grep, Write, Edit

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Inventory secrets and flows
  2. Harden OAuth
  3. Minimize authorization
  4. Harden data and logs
  5. Verify webhooks
  6. Harden dependencies and deployment
  7. Prove controls

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • canva.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires a backend web application, approved secret store, threat owner, and current Canva security documentation.

    From compatibility in the SKILL.md frontmatter.

Context cost

Canva Security Basics loads about 1.1k tokens when it runs, and up to ~1.2k if it reads all its reference files. Until then it costs about 83 tokens; SKILL.md has 433 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 433 words, ~1,067 tokens.

Download SKILL.mdSave it as .claude/skills/canva-security-basics/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
canva-security-basics
description
Implement the Canva Connect security baseline for backend OAuth, least privilege, tenant isolation, logging, revocation, and preview webhook verification. Use when threat-modeling, reviewing, or hardening an integration. Trigger with: "secure Canva integration", "Canva token security", "verify Canva webhook".
allowed-tools
Read, Grep, Write, Edit
compatibility
Requires a backend web application, approved secret store, threat owner, and current Canva security documentation.
version
2.0.0
argument-hint
[integration-id-and-threat-scope]
model
inherit
effort
high
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, canva, security, operations

Canva Integration Security Baseline

Overview

Protect client secrets and user tokens as separate high-impact credentials. Enforce authorization before provider access and treat preview webhook verification as an additional boundary, not proof of business authorization.

Prerequisites

  • Integration ID, environments, operations, tenants, and threat scope
  • Current scopes, redirect URIs, token stores, and data flows
  • Webhook/preview use, incident response, secret scanning, and audit controls

Instructions

Step 1: Inventory secrets and flows

Use Read and Grep to locate client secrets, access/refresh tokens, PKCE verifier, OAuth state, callbacks, browser bundles, logs, backups, jobs, and external processors.

Step 2: Harden OAuth

Require controlled redirect hosts, one-time state/verifier, backend token exchange, encrypted and separated tokens, per-user refresh serialization, revocation, and disconnect cleanup.

Step 3: Minimize authorization

Request explicit minimum scopes and enforce tenant, resource, role, capability, purpose, and preview status server-side before every action.

Step 4: Harden data and logs

Use Write or Edit to prevent tokens, bodies, signed URLs, personal data, and resource identifiers from routine logs; protect stored content and deletion workflows.

Step 5: Verify webhooks

For authorized preview use, validate the signed token/claims against cached Canva JWKs, select by case-sensitive key ID, refetch only for unknown keys, enforce replay/idempotency controls, and authorize resulting actions separately.

Step 6: Harden dependencies and deployment

Pin provider/client inputs, scan secrets, isolate environments, protect CI from forks, deploy immutably, and maintain tested rollback and credential rotation.

Step 7: Prove controls

Test state mismatch, token leak prevention, cross-tenant denial, refresh races, scope denial, unknown webhook key, replay, revoked consent, and account deletion.

Show full SKILL.md (181 more words)Show less

Authentication

Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.

Tool Discipline

Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.

Output

  • Scoped decision or implementation artifact
  • Redacted operation and validation receipt
  • Failure, rollback, and follow-up ownership record

Examples

A valid Canva webhook signature is accepted only as authenticity evidence. The router still checks preview authorization, tenant/resource policy, idempotency, and allowed action before processing.

Error Handling

FailureResponse
Secret reaches public repositoryAssume compromise, rotate, and investigate
Cross-tenant access succeedsDisable the path and treat as a security incident
Webhook key is unknownRefetch the public JWK set once and fail closed if still unknown
Consent is revokedDelete tokens and deny queued work

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/canva-security-basics of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Canva Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Canva Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Canva Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
Security Threat Modelingdevcodex-labs/devcodex439—~771Automated safety check: PassAGPL-3.0
PR Review Provideryansongda/pay5.4k—~2.4kAutomated safety check: PassMIT
Stripe Best Practiceskanchengw/cnllm1732 repos~925Automated safety check: PassApache-2.0
Discord Php Bot Securitydiscord-php/DiscordPHP1.1k—~1.2kAutomated safety check: NotesMIT
GitHub OAuth Nango IntegrationAgentWorkforce/relay8721 repos~3.4kAutomated safety check: PassApache-2.0

Similar skills

  • Security Threat Modeling

    devcodex-labs/devcodex

    安全威胁建模专家 Owner — 当任务涉及权限、认证、授权、输入输出信任边界、密钥策略、审计、攻击面、Webhook/OAuth、敏感操作或用户要求安全专家视角时使用;要求识别滥用路径并绑定缓解验证。

    439 GitHub stars~771 tokensUpdated 24 days ago
    Backend & APIsAuto-check passed
  • PR Review Provider

    yansongda/pay

    A skill your agent uses when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.

    5.4k GitHub stars~2.4k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Stripe Best Practices

    kanchengw/cnllm

    Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…

    173 GitHub starsUsed in 2 repos~925 tokens
    Backend & APIsAuto-check passed
  • Discord Php Bot Security

    discord-php/DiscordPHP

    Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of customids and exception messages, use constant-time comparison and…

    1.1k GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check: notes
  • GitHub OAuth Nango Integration

    AgentWorkforce/relay

    A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling

    872 GitHub starsUsed in 1 repo~3.4k tokens
    Backend & APIsAuto-check passed
  • Rails Security Multitenancy

    marckohlbrugge/37signals-skills

    Apply Rails security and multi-tenant safety practices including scoped queries, SSRF defenses, rate limiting, and tenant-scoped realtime updates.

    724 GitHub stars~1.7k tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Canva Security Basics

What does Canva Security Basics do?

Implement the Canva Connect security baseline for backend OAuth, least privilege, tenant isolation, logging, revocation, and preview webhook verification. Canva Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement the Canva Connect security baseline for backend OAuth, least privilege, tenant isolation, logging, revocation, and preview webhook verification.

When should I use Canva Security Basics?

Canva Security Basics fits situations like: threat-modeling; hardening an integration; with: secure Canva integration; canva token security.

How do I install Canva Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/canva-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/canva-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Canva Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-security-basics -a codex`. Or copy the skill folder (skills/.curated/canva-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/canva-security-basics in your project. Codex loads it when a task matches its description.

Can I use Canva Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/canva-security-basics, .gemini/skills/canva-security-basics, .github/skills/canva-security-basics and .opencode/skills/canva-security-basics in your project.

What does Canva Security Basics need to run?

SKILL.md names no scripts, command-line tools or credentials: Canva Security Basics is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Write, Edit. Compatibility (from SKILL.md): Requires a backend web application, approved secret store, threat owner, and current Canva security documentation..

Does Canva Security Basics access the network?

SKILL.md names 1 domain. As links in the text: canva.dev. This is read from the text; nothing was executed.

Is Canva Security Basics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Canva Security Basics use?

Canva Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Canva Security Basics use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 134 tokens, read only when the agent opens those files.

What are the alternatives to Canva Security Basics?

Skills that share tags, products or a category with Canva Security Basics: Security Threat Modeling (devcodex-labs/devcodex, 439 stars), PR Review Provider (yansongda/pay, 5.4k stars), Stripe Best Practices (kanchengw/cnllm, 173 stars) and Discord Php Bot Security (discord-php/DiscordPHP, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Canva Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.