pencil-ui-designer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill functions as a router, processing user-provided requirements to determine which sub-skill to invoke. This creates a potential surface for indirect prompt injection; however, the skill explicitly mandates intent verification, requiring the user to mention 'Pencil' specifically before proceeding, which mitigates accidental or malicious triggering through general conversation.
  • [SAFE]: The skill does not perform any network operations, file system access, or command execution. It contains no hardcoded credentials or obfuscated content. The logic is restricted to mapping user framework preferences (e.g., Bootstrap, Ant Design) to the appropriate internal tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 03:04 PM
Security Audit — agent-trust-hub — pencil-ui-designer