penpot-uiux-design

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs users to clone the official Penpot MCP repository from GitHub. As this is a well-known service related to the skill's primary function, it is considered safe configuration.
  • [COMMAND_EXECUTION]: Includes standard shell commands for installing dependencies and building the local server environment using npm. These are necessary steps for the described tool setup.
  • [REMOTE_CODE_EXECUTION]: Leverages the mcp__penpot__execute_code tool to automate design tasks within the Penpot environment. This dynamic execution is the core functionality of the skill and is constrained to the Penpot plugin context.
  • [PROMPT_INJECTION]: The skill processes existing design data (shapes, text, and styles) from the Penpot workspace to inform the agent's actions. This introduces an indirect prompt injection surface, though the risk is localized to the user's design project.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 05:09 PM
Security Audit — agent-trust-hub — penpot-uiux-design