ui-convert-writer-paper

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill reads local design data from the .ui-convert/ir/ directory and maintains state in registry.json. This access is necessary for the conversion process and is confined to the local project environment. No network operations or external communication patterns were detected that would facilitate data exfiltration.
  • [COMMAND_EXECUTION]: All interactions with the Paper design environment are performed through specific, pre-defined Model Context Protocol (MCP) tool signatures (e.g., create_frame, create_text). The skill does not use shell-based command execution or other high-risk system calls.
  • [REMOTE_CODE_EXECUTION]: The skill does not download external scripts or execute remote code. It follows a static, rule-based conversion logic for processing local IR files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 08:01 PM