ui-convert-mcp-validator
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill verifies the ability to access design context through tools like
get_screenshotandget_editor_state. These read operations are limited to the design tool environment and are necessary for validating the pipeline preflight status. - [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external data by ingesting tool listings and server responses during validation.
- Ingestion points: Status probe responses and tool listings from MCP servers.
- Boundary markers: Not defined.
- Capability inventory: Read-only status checks and tool discovery.
- Sanitization: Not specified.
- [EXTERNAL_DOWNLOADS]: The skill references troubleshooting documentation from the official pencil.dev domain for resolving connectivity issues.
Audit Metadata