pencil-mcp-open-document
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious behavior, obfuscation, or unauthorized network access detected. The skill serves a legitimate purpose of managing design files.
- [PROMPT_INJECTION]: The skill incorporates protective instructions requiring the agent to verify explicit user intent (specifically mentioning "Pencil") before executing the
open_documenttool, which prevents accidental or forced tool usage. - [DATA_EXPOSURE]: The skill handles absolute file paths for opening design documents. This access is strictly gated by the requirement for explicit user requests within the context of design tasks.
Audit Metadata