penpot-design-md

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for the legitimate task of generating design documentation (DESIGN.md) from Penpot files.
  • [COMMAND_EXECUTION]: The skill utilizes the execute_code tool to run internal JavaScript scripts within the Penpot environment for the purpose of data extraction. These scripts are provided within the skill's package and are limited to reading design properties.
  • [DATA_EXPOSURE]: Data access is confined to design-related information (tokens, components, layout properties) within the active Penpot file. The skill does not access local system files, environment variables, or credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 01:09 PM
Security Audit — agent-trust-hub — penpot-design-md