pencil-mcp-set-variables
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill incorporates explicit intent recognition instructions, requiring the agent to verify that the user is specifically referring to the "Pencil" design tool before proceeding. This acts as a safeguard against accidental misuse where design variable commands might otherwise be applied to sensitive files like environment configurations.
- [SAFE]: No evidence of malicious patterns such as prompt injection, data exfiltration, or unauthorized network operations was found. The skill instructions focus on valid usage of the
set_variablestool with structured JSON data. - [SAFE]: All external references, such as the
filePathparameter for.penfiles, are consistent with the skill's stated purpose of maintaining a design token system.
Audit Metadata