pencil-mcp-replace-all-matching-properties

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill focuses on design-related tasks within the Pencil environment and includes explicit guardrails to ensure the agent verifies user intent before execution.
  • [PROMPT_INJECTION]: Evaluated for indirect prompt injection surface. Ingestion points: replacement rules in the 'properties' array (SKILL.md); Boundary markers: Absent; Capability inventory: replace_all_matching_properties tool; Sanitization: None. The risk is assessed as negligible because the tool's capabilities are restricted to modifying design properties (colors, fonts) within a design tool, with no access to sensitive system resources or network exfiltration paths.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 04:06 PM
Security Audit — agent-trust-hub — pencil-mcp-replace-all-matching-properties