pencil-mcp-get-editor-state

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill documentation describes a legitimate use case for retrieving design environment state from a Pencil MCP tool without any malicious behavior.
  • [NO_CODE]: The skill package does not contain any scripts, binaries, or executable logic; it is composed entirely of markdown documentation and a standard Apache License 2.0 text.
  • [PROMPT_INJECTION]: The 'CRITICAL' instructions found in the documentation are functional guardrails designed to restrict the agent's use of the tool to appropriate contexts (when 'Pencil' is explicitly mentioned), which is a benign and defensive instructional practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 05:22 PM