pencil-mcp-get-variables

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes design tokens from external files, establishing a surface for indirect prompt injection.\n
  • Ingestion points: Design data is ingested from local .pen files through the get_variables tool call as described in SKILL.md.\n
  • Boundary markers: The instructions do not provide delimiters or warnings to isolate external data from the agent's core instructions.\n
  • Capability inventory: The retrieved variable values are used to execute batch_design operations, meaning untrusted content could influence agent-initiated design changes (SKILL.md).\n
  • Sanitization: The skill lacks instructions for validating or escaping the content of the design tokens before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 01:30 AM
Security Audit — agent-trust-hub — pencil-mcp-get-variables