ui-convert-mcp-validator

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill verifies the ability to access design context through tools like get_screenshot and get_editor_state. These read operations are limited to the design tool environment and are necessary for validating the pipeline preflight status.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external data by ingesting tool listings and server responses during validation.
  • Ingestion points: Status probe responses and tool listings from MCP servers.
  • Boundary markers: Not defined.
  • Capability inventory: Read-only status checks and tool discovery.
  • Sanitization: Not specified.
  • [EXTERNAL_DOWNLOADS]: The skill references troubleshooting documentation from the official pencil.dev domain for resolving connectivity issues.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 02:27 PM