penpot-audit-tokens
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No prompt injection patterns or instructions to bypass safety guidelines were found. The workflow is strictly defined for design auditing purposes.\n- [SAFE]: No data exfiltration or unauthorized data exposure was detected. The skill only accesses design properties required for auditing and does not interact with external domains or sensitive local files.\n- [SAFE]: No obfuscation, hidden characters, or encoded payloads were identified in the markdown or script files.\n- [SAFE]: The skill uses local scripts provided within the skill package to perform analysis via the Penpot API. It does not download or execute remote code from external sources.\n- [SAFE]: The skill does not request or use elevated privileges, persistence mechanisms, or unauthorized system access.
Audit Metadata