pencil-to-code

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns detected. The skill follows its stated purpose of converting design files to code using specified tool calls.
  • [PROMPT_INJECTION]: The skill ingests data from external design files, creating a surface for indirect prompt injection.
  • Ingestion points: Reads .pen files using mcp__pencil__batch_get.
  • Boundary markers: Absent.
  • Capability inventory: Generates executable React and Tailwind code.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 07:45 PM
Security Audit — agent-trust-hub — pencil-to-code