pencil-mcp-get-style-guide

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, data exfiltration, or remote code execution risks were detected. The skill primarily focuses on providing instructional context for calling an MCP tool named get_style_guide.
  • [PROMPT_INJECTION]: The skill contains strict usage instructions (e.g., "You must ONLY use this skill when the user EXPLICITLY mentions 'Pencil'"). These are benign constraints designed to narrow the agent's focus and prevent accidental tool usage rather than malicious bypass attempts.
  • [DATA_EXFILTRATION]: No sensitive file access or unauthorized network operations were identified. The parameters used (id, tags) are standard for metadata retrieval.
  • [REMOTE_CODE_EXECUTION]: There is no evidence of external script downloads, package installations, or dynamic code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 10:48 AM