CanvasSAFE
Version 2.2 - 54 tools available - an MCP server for interacting with the Canvas LMS API. This server allows you to manage courses, assignments, enrollments, and grades within Canvas.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Security and disclosure history
This project is an independent MCP server for Canvas LMS APIs. It is not affiliated with, endorsed by, or maintained by Instructure or Canvas.
In June 2025, during development of this MCP, I identified a Broken Access Control issue in the Canvas environment at bootcampspot.instructure.com. The issue exposed personally identifiable information for other students enrolled in my course.
I reported the issue through Bugcrowd on June 5, 2025, and also contacted Instructure / Canvas security channels directly. The Bugcrowd report was later closed as "Not Applicable." In subsequent correspondence, Instructure stated that the bootcampspot.instructure.com environment was outside its control.
Public references:
- Disclosure thread: https://www.reddit.com/r/cybersecurity/comments/1t6wmkw/reportedabrokenaccesscontrolbugto/
- Bugcrowd activity timeline: https://imgur.com/gallery/canvas-vuln-declared-n-11-months-ago-zYfHnBs
- Later Instructure / BootcampSpot correspondence: https://imgur.com/a/BnhgXme
This repository does not publish exploit steps, affected tenant details beyond what is already public, live URLs, screenshots containing student data, or proof-of-concept abuse flows.
Separately, Instructure publicly disclosed a Canvas security incident in May 2026, and public reporting has linked the incident to ShinyHunters claims. This repository makes no claim that the June 2025 report caused, enabled, predicted, or is technically connected to the May 2026 incident.
This disclosure is documented here for project history and transparency only.
What this is
A comprehensive Model Context Protocol (MCP) server for Canvas LMS with complete student, instructor, and account administration functionality
🚀 What's New in v2.3.0
- 🌐 NEW: Streamable HTTP transport support (
MCP_TRANSPORT=streamable-http) - 🖥️ Preserved: First-class stdio transport for local MCP clients
- 🧪 Added: Behavior tes
b629aa77a709OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add canvas-mcp-server --env CANVAS_ACCESS_TOKEN=${CANVAS_ACCESS_TOKEN} --env CANVAS_TEST_TOKEN=${CANVAS_TEST_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"canvas-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CANVAS_ACCESS_TOKEN": "${CANVAS_ACCESS_TOKEN}",
"CANVAS_TEST_TOKEN": "${CANVAS_TEST_TOKEN}"
}
}
}
}Exposed tools (54)
41 read · 13 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
canvas_create_account_report | write | Generate a report for an account |
canvas_create_assignment | write | Create a new assignment in a Canvas course |
canvas_create_conversation | write | Create a new conversation |
canvas_create_course | write | Create a new course in Canvas |
canvas_create_quiz | write | Create a new quiz in a course |
canvas_create_user | write | Create a new user in an account |
canvas_enroll_user | read | Enroll a user in a course |
canvas_get_account | read | Get account details |
canvas_get_account_reports | read | List available reports for an account |
canvas_get_assignment | read | Get detailed information about a specific assignment |
canvas_get_conversation | read | Get details of a specific conversation |
canvas_get_course | read | Get detailed information about a specific course |
canvas_get_course_grades | read | Get grades for a course |
canvas_get_dashboard | read | Get user |
canvas_get_dashboard_cards | read | Get dashboard course cards |
canvas_get_discussion_topic | read | Get details of a specific discussion topic |
canvas_get_file | read | Get information about a specific file |
canvas_get_module | read | Get details of a specific module |
canvas_get_module_item | read | Get details of a specific module item |
canvas_get_page | read | Get content of a specific page |
canvas_get_quiz | read | Get details of a specific quiz |
canvas_get_rubric | read | Get details of a specific rubric |
canvas_get_submission | read | Get submission details for an assignment |
canvas_get_syllabus | read | Get course syllabus |
canvas_get_upcoming_assignments | read | Get upcoming assignment due dates |
canvas_get_user_grades | read | Get all grades for the current user |
canvas_get_user_profile | read | Get current user |
canvas_health_check | read | Check the health and connectivity of the Canvas API |
canvas_list_account_courses | read | List courses for an account |
canvas_list_account_users | read | List users for an account |
canvas_list_announcements | read | List all announcements in a course |
canvas_list_assignment_groups | read | List assignment groups for a course |
canvas_list_assignments | read | List assignments for a course |
canvas_list_calendar_events | read | List calendar events |
canvas_list_conversations | read | List user |
canvas_list_courses | read | List all courses for the current user |
canvas_list_discussion_topics | read | List all discussion topics in a course |
canvas_list_files | read | List files in a course or folder |
canvas_list_folders | read | List folders in a course |
canvas_list_module_items | read | List all items in a module |
canvas_list_modules | read | List all modules in a course |
canvas_list_notifications | read | List user |
canvas_list_pages | read | List pages in a course |
canvas_list_quizzes | read | List all quizzes in a course |
canvas_list_rubrics | read | List rubrics for a course |
canvas_list_sub_accounts | read | List sub-accounts for an account |
canvas_mark_module_item_complete | read | Mark a module item as complete |
canvas_post_to_discussion | write | Post a message to a discussion topic |
canvas_start_quiz_attempt | write | Start a new quiz attempt |
canvas_submit_assignment | write | Submit work for an assignment |
canvas_submit_grade | write | Submit a grade for a student |
canvas_update_assignment | write | Update an existing assignment |
canvas_update_course | write | Update an existing course in Canvas |
canvas_update_user_profile | write | Update current user |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
@modelcontextprotocol/sdk, axios, dotenv, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, @vitest/coverage-v8, concurrently
Gates applied: no_behavioural_pass, no_license.
b629aa77a709full audit observations/trust-audit/mcp-server/dmontgomery40__canvas-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b629aa77a709 | SAFE | B | 89 | first audit |
Questions
What is the Canvas MCP server?
Version 2.2 - 54 tools available - an MCP server for interacting with the Canvas LMS API. This server allows you to manage courses, assignments, enrollments, and grades within Canvas.
What tools does Canvas expose?
54 in total: 41 read-only, 13 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Canvas safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Canvas need?
It reads CANVAS_ACCESS_TOKEN and CANVAS_TEST_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Canvas run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as canvas-mcp-server at 2.3.1.
How current is this page?
The grade is for one exact copy of the source (b629aa77a709), read on 2026-10-07. The repository is watched and re-audited when it changes.