pencil-mcp-open-document
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill accepts absolute file paths as input for the
open_documenttool. This functionality could be exploited to read sensitive files on the host system, such as configuration files or credentials, if the agent is directed to paths outside of the design context. Evidence found in SKILL.md and example files.- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it loads content from external files without providing sanitization or clear boundary markers to the agent. Ingestion points:filePathOrTemplateparameter in SKILL.md. Boundary markers: Absent. Capability inventory:open_documenttool (reads file content). Sanitization: Absent.
Audit Metadata