Atlas / MCP servers / dmontgomery40 / Canvas

CanvasSAFE

mcp/dmontgomery40/canvas-2

Version 2.2 - 54 tools available - an MCP server for interacting with the Canvas LMS API. This server allows you to manage courses, assignments, enrollments, and grades within Canvas.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
54 41r · 13w · 0d
Transport
stdio · streamable-http
License
—
Stars
103
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Security and disclosure history

This project is an independent MCP server for Canvas LMS APIs. It is not affiliated with, endorsed by, or maintained by Instructure or Canvas.

In June 2025, during development of this MCP, I identified a Broken Access Control issue in the Canvas environment at bootcampspot.instructure.com. The issue exposed personally identifiable information for other students enrolled in my course.

I reported the issue through Bugcrowd on June 5, 2025, and also contacted Instructure / Canvas security channels directly. The Bugcrowd report was later closed as "Not Applicable." In subsequent correspondence, Instructure stated that the bootcampspot.instructure.com environment was outside its control.

Public references:

  • Disclosure thread: https://www.reddit.com/r/cybersecurity/comments/1t6wmkw/reportedabrokenaccesscontrolbugto/
  • Bugcrowd activity timeline: https://imgur.com/gallery/canvas-vuln-declared-n-11-months-ago-zYfHnBs
  • Later Instructure / BootcampSpot correspondence: https://imgur.com/a/BnhgXme

This repository does not publish exploit steps, affected tenant details beyond what is already public, live URLs, screenshots containing student data, or proof-of-concept abuse flows.

Separately, Instructure publicly disclosed a Canvas security incident in May 2026, and public reporting has linked the incident to ShinyHunters claims. This repository makes no claim that the June 2025 report caused, enabled, predicted, or is technically connected to the May 2026 incident.

This disclosure is documented here for project history and transparency only.

What this is

A comprehensive Model Context Protocol (MCP) server for Canvas LMS with complete student, instructor, and account administration functionality

🚀 What's New in v2.3.0

  • 🌐 NEW: Streamable HTTP transport support (MCP_TRANSPORT=streamable-http)
  • 🖥️ Preserved: First-class stdio transport for local MCP clients
  • 🧪 Added: Behavior tes
Read from source at commit b629aa77a709OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add canvas-mcp-server --env CANVAS_ACCESS_TOKEN=${CANVAS_ACCESS_TOKEN} --env CANVAS_TEST_TOKEN=${CANVAS_TEST_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "canvas-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CANVAS_ACCESS_TOKEN": "${CANVAS_ACCESS_TOKEN}",
        "CANVAS_TEST_TOKEN": "${CANVAS_TEST_TOKEN}"
      }
    }
  }
}
03

Exposed tools (54)

41 read · 13 write · 0 destructive.

ToolRiskDescription
canvas_create_account_reportwriteGenerate a report for an account
canvas_create_assignmentwriteCreate a new assignment in a Canvas course
canvas_create_conversationwriteCreate a new conversation
canvas_create_coursewriteCreate a new course in Canvas
canvas_create_quizwriteCreate a new quiz in a course
canvas_create_userwriteCreate a new user in an account
canvas_enroll_userreadEnroll a user in a course
canvas_get_accountreadGet account details
canvas_get_account_reportsreadList available reports for an account
canvas_get_assignmentreadGet detailed information about a specific assignment
canvas_get_conversationreadGet details of a specific conversation
canvas_get_coursereadGet detailed information about a specific course
canvas_get_course_gradesreadGet grades for a course
canvas_get_dashboardreadGet user
canvas_get_dashboard_cardsreadGet dashboard course cards
canvas_get_discussion_topicreadGet details of a specific discussion topic
canvas_get_filereadGet information about a specific file
canvas_get_modulereadGet details of a specific module
canvas_get_module_itemreadGet details of a specific module item
canvas_get_pagereadGet content of a specific page
canvas_get_quizreadGet details of a specific quiz
canvas_get_rubricreadGet details of a specific rubric
canvas_get_submissionreadGet submission details for an assignment
canvas_get_syllabusreadGet course syllabus
canvas_get_upcoming_assignmentsreadGet upcoming assignment due dates
canvas_get_user_gradesreadGet all grades for the current user
canvas_get_user_profilereadGet current user
canvas_health_checkreadCheck the health and connectivity of the Canvas API
canvas_list_account_coursesreadList courses for an account
canvas_list_account_usersreadList users for an account
canvas_list_announcementsreadList all announcements in a course
canvas_list_assignment_groupsreadList assignment groups for a course
canvas_list_assignmentsreadList assignments for a course
canvas_list_calendar_eventsreadList calendar events
canvas_list_conversationsreadList user
canvas_list_coursesreadList all courses for the current user
canvas_list_discussion_topicsreadList all discussion topics in a course
canvas_list_filesreadList files in a course or folder
canvas_list_foldersreadList folders in a course
canvas_list_module_itemsreadList all items in a module
canvas_list_modulesreadList all modules in a course
canvas_list_notificationsreadList user
canvas_list_pagesreadList pages in a course
canvas_list_quizzesreadList all quizzes in a course
canvas_list_rubricsreadList rubrics for a course
canvas_list_sub_accountsreadList sub-accounts for an account
canvas_mark_module_item_completereadMark a module item as complete
canvas_post_to_discussionwritePost a message to a discussion topic
canvas_start_quiz_attemptwriteStart a new quiz attempt
canvas_submit_assignmentwriteSubmit work for an assignment
canvas_submit_gradewriteSubmit a grade for a student
canvas_update_assignmentwriteUpdate an existing assignment
canvas_update_coursewriteUpdate an existing course in Canvas
canvas_update_user_profilewriteUpdate current user
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, dotenv, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, @vitest/coverage-v8, concurrently
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha b629aa77a709full audit observations/trust-audit/mcp-server/dmontgomery40__canvas-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b629aa77a709SAFEB89first audit
06

Questions

What is the Canvas MCP server?

Version 2.2 - 54 tools available - an MCP server for interacting with the Canvas LMS API. This server allows you to manage courses, assignments, enrollments, and grades within Canvas.

What tools does Canvas expose?

54 in total: 41 read-only, 13 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Canvas safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Canvas need?

It reads CANVAS_ACCESS_TOKEN and CANVAS_TEST_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Canvas run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as canvas-mcp-server at 2.3.1.

How current is this page?

The grade is for one exact copy of the source (b629aa77a709), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement