pencil-mcp-open-document

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accepts absolute file paths as input for the open_document tool. This functionality could be exploited to read sensitive files on the host system, such as configuration files or credentials, if the agent is directed to paths outside of the design context. Evidence found in SKILL.md and example files.- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it loads content from external files without providing sanitization or clear boundary markers to the agent. Ingestion points: filePathOrTemplate parameter in SKILL.md. Boundary markers: Absent. Capability inventory: open_document tool (reads file content). Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 04:14 AM
Security Audit — agent-trust-hub — pencil-mcp-open-document