penpot-uiux-design
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE] (SAFE): The skill consists entirely of Markdown reference files with no executable scripts (.py, .js, .sh) or active instructions that could be autonomously executed by an agent.- [EXTERNAL_DOWNLOADS] (LOW): The setup documentation references an external GitHub repository (penpot/penpot-mcp) and the 'mcp-remote' npm package. While these are third-party sources not on the pre-approved trusted list, they are standard components of the integration described and require manual user intervention to install.- [COMMAND_EXECUTION] (SAFE): The provided documentation includes bash commands for installation and troubleshooting (e.g., git clone, npm install). These are presented as educational content for manual setup and do not involve automated command execution within the skill's logic.
Audit Metadata