canvas-mcp
Manage coursework across Canvas and Gradescope: find relevant resources, browse courses and modules, and retrieve direct file links. Track upcoming assignments and submission status, and surface details by course name or natural-language query.
0Tools
2Findings
Mar 24, 2026Last Scanned
1 medium ยท 1 low findings detected
Security Category Deep Dive
Prompt Injection
Prompt & context manipulation attacks
69
Maturity
14
Rules
5
Sub-Categories
1
Gaps
64%
Implemented
56
Tests
1
Stories
100%3 rules
Injection via tool descriptions and parameter fields
GAP-001Prompt Injection Coverage GapMissing detection coverage for emerging prompt injection attack variants not addressed by current rules
100%4 rules
Hidden instructions via external content and tool responses
100%2 rules
Context window saturation and prior-approval exploitation
100%3 rules
Payload hiding via invisible chars, base64, schema fields
100%2 rules
Injection via prompt templates and runtime tool output