mcp-canvas-lms — security grade SAFE, quality 73/100

Security audit verdict: SAFE · quality 73/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by DMontgomery40 · MCP Server · ★ 102

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is mcp-canvas-lms safe to install? View the security audit →

About mcp-canvas-lms

Canvas MCP Server v2.3.0 Security and disclosure history This project is an independent MCP server for Canvas LMS APIs. It is not affiliated with, endorsed by, or maintained by Instructure or Canvas. In June 2025, during development of this MCP, I identified a Broken Access Control issue in the Canvas environment at bootcampspot.instructure.com. The issue exposed personally identifiable information for other students enrolled in my course. I reported the issue through Bugcrowd on June 5, 2025, and also contacted Instructure / Canvas security channels directly. The Bugcrowd report was later closed as "Not Applicable." In subsequent correspondence, Instructure stated that the bootcampspot.instructure.com environment was outside its control.

canvas-lmscanvas-lms-apicanvas-lms-gradesmcpmcp-education-toolmcp-servermodel-context-protocolschool-education

Quick Facts

Stars102
Forks39
LanguageJavaScript
CategoryMCP Server
Quality Score72.6801974806477/100
Open Issues4
Last Updated2026-05-31
Created2024-12-05
Platformsmcp, node
Est. Tokens~360k

Compatible Skills

These tools work well together with mcp-canvas-lms for enhanced workflows:

  • opencove — semantic(0.30)+complementary+similar_pop+shared_platform (46%)
  • open-research-ANA — semantic(0.15)+complementary+similar_pop+shared_platform (45%)

mcp-canvas-lms alternative? Top 4 similar tools

Looking for a mcp-canvas-lms alternative? If you're comparing mcp-canvas-lms with other mcp server tools, these 4 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • vibe-check-mcp-server by PV-Bhat · ⭐ 502

    Vibe Check is a tool that provides mentor-like feedback to AI Agents, preventing tunnel-vision, over-engineeri

  • airtable-mcp-server by domdomegg · ⭐ 456

    🗂️🤖 Airtable Model Context Protocol Server, for allowing AI systems to interact with your Airtable bases

  • mcp-server by e2b-dev · ⭐ 394

    Giving Claude ability to run code with E2B via MCP (Model Context Protocol)

  • canvas-pilot by X-isdoingreat · ⭐ 121

    Local-first Canvas LMS AI agent that learns each course's recurring assignment workflow and reuses it through

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular JavaScript Agent Tools

Frequently Asked Questions

What is mcp-canvas-lms?

mcp-canvas-lms is Version 2.2 - 54 tools available - an MCP server for interacting with the Canvas LMS API. This server allows you to manage courses, assignments, enrollments, and grades within Canvas.. It is categorized as a MCP Server with 102 GitHub stars.

What programming language is mcp-canvas-lms written in?

mcp-canvas-lms is primarily written in JavaScript. It covers topics such as canvas-lms, canvas-lms-api, canvas-lms-grades.

How do I install or use mcp-canvas-lms?

You can find installation instructions and usage details in the mcp-canvas-lms GitHub repository at github.com/DMontgomery40/mcp-canvas-lms. The project has 102 stars and 39 forks, indicating an active community.

What are the best alternatives to mcp-canvas-lms?

The top alternatives to mcp-canvas-lms on Agent Skills Hub include vibe-check-mcp-server, airtable-mcp-server, mcp-server. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools