penpot-build-from-code

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates entirely within the Penpot platform environment. It uses local JavaScript scripts to manipulate UI elements via the Penpot API, which is a restricted and platform-specific execution context.\n- [SAFE]: No network operations or data exfiltration patterns were identified. The skill does not use tools like curl, wget, or fetch, ensuring that code and design data remain local.\n- [SAFE]: The skill implements a robust design system governance model, requiring all styles to be bound to existing tokens and library components. This prevents the execution of unverified or hardcoded values.\n- [SAFE]: No obfuscation techniques, such as Base64 encoding of commands or hidden characters, were found in the instructions or scripts.\n- [SAFE]: The skill lacks dangerous capabilities such as arbitrary shell command execution, persistence mechanisms, or privilege escalation. All script operations are additive and localized to the Penpot canvas.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 01:09 PM
Security Audit — agent-trust-hub — penpot-build-from-code