pencil-design
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE] (SAFE): The provided files consist entirely of design guidelines, reference tables, and checklists. No malicious instructions, obfuscation, or data exfiltration patterns were detected.\n- [NO_CODE] (SAFE): The skill contains no executable scripts (e.g., .py, .js, .sh) or binaries. Its logic is based on prompt-based instructions and reference materials.\n- [Indirect Prompt Injection] (SAFE): The skill includes instructions to read and process external Pencil design files (via
pencil_batch_get). While this constitutes an untrusted data ingestion surface, the risk is considered low/safe because the skill is focused on design mapping and does not possess high-privilege capabilities or command execution tools.
Audit Metadata