penpot-uiux-design
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs users to clone the official Penpot MCP repository from GitHub. As this is a well-known service related to the skill's primary function, it is considered safe configuration.
- [COMMAND_EXECUTION]: Includes standard shell commands for installing dependencies and building the local server environment using npm. These are necessary steps for the described tool setup.
- [REMOTE_CODE_EXECUTION]: Leverages the
mcp__penpot__execute_codetool to automate design tasks within the Penpot environment. This dynamic execution is the core functionality of the skill and is constrained to the Penpot plugin context. - [PROMPT_INJECTION]: The skill processes existing design data (shapes, text, and styles) from the Penpot workspace to inform the agent's actions. This introduces an indirect prompt injection surface, though the risk is localized to the user's design project.
Audit Metadata