penpot-build-screen
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns detected. The skill uses a structured workflow for senior-level design tasks within the Penpot ecosystem.
- [COMMAND_EXECUTION]: The skill uses
execute_codeto perform legitimate Penpot API operations such ascreateBoard,addFlexLayout, andapplyToken. These are standard functionalities for the intended platform and do not involve shell access or unauthorized commands. - [DATA_EXFILTRATION]: No network operations or sensitive file access patterns were found. The tool communicates solely through the provided Penpot MCP interface and local storage ledgers for state management.
- [PROMPT_INJECTION]: The instructions contain strict internal rules (e.g., 'The One Rule That Matters Most') but they are directed at ensuring design quality and design system compliance rather than attempting to bypass safety filters or override agent behavior in a malicious way.
- [REMOTE_CODE_EXECUTION]: The scripts included are helper utilities for layout auditing and component instantiation. They are local to the skill's context and do not download or execute remote scripts from external servers.
Audit Metadata