pencil-mcp-set-variables

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill incorporates explicit intent recognition instructions, requiring the agent to verify that the user is specifically referring to the "Pencil" design tool before proceeding. This acts as a safeguard against accidental misuse where design variable commands might otherwise be applied to sensitive files like environment configurations.
  • [SAFE]: No evidence of malicious patterns such as prompt injection, data exfiltration, or unauthorized network operations was found. The skill instructions focus on valid usage of the set_variables tool with structured JSON data.
  • [SAFE]: All external references, such as the filePath parameter for .pen files, are consistent with the skill's stated purpose of maintaining a design token system.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 04:14 AM
Security Audit — agent-trust-hub — pencil-mcp-set-variables