pencil-mcp-batch-get

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Analysis of the skill's instructions, metadata, and provided tools reveals no malicious behavior, obfuscated code, or unauthorized network operations.
  • [PROMPT_INJECTION]: The skill processes external data via the filePath parameter, creating a potential surface for indirect prompt injection. * Ingestion points: Data enters the agent context through the filePath parameter in SKILL.md. * Boundary markers: There are no specific boundary markers or instructions to ignore embedded commands within the processed file data. * Capability inventory: The skill utilizes the batch_get tool to retrieve node properties and hierarchical structures. * Sanitization: No explicit content validation or sanitization routines are described in the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 05:22 PM