penpot-build-from-code
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates entirely within the Penpot platform environment. It uses local JavaScript scripts to manipulate UI elements via the Penpot API, which is a restricted and platform-specific execution context.\n- [SAFE]: No network operations or data exfiltration patterns were identified. The skill does not use tools like
curl,wget, orfetch, ensuring that code and design data remain local.\n- [SAFE]: The skill implements a robust design system governance model, requiring all styles to be bound to existing tokens and library components. This prevents the execution of unverified or hardcoded values.\n- [SAFE]: No obfuscation techniques, such as Base64 encoding of commands or hidden characters, were found in the instructions or scripts.\n- [SAFE]: The skill lacks dangerous capabilities such as arbitrary shell command execution, persistence mechanisms, or privilege escalation. All script operations are additive and localized to the Penpot canvas.
Audit Metadata