pencil-mcp-get-editor-state
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill documentation describes a legitimate use case for retrieving design environment state from a Pencil MCP tool without any malicious behavior.
- [NO_CODE]: The skill package does not contain any scripts, binaries, or executable logic; it is composed entirely of markdown documentation and a standard Apache License 2.0 text.
- [PROMPT_INJECTION]: The 'CRITICAL' instructions found in the documentation are functional guardrails designed to restrict the agent's use of the tool to appropriate contexts (when 'Pencil' is explicitly mentioned), which is a benign and defensive instructional practice.
Audit Metadata