penpot-document-handoff
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for Penpot design documentation and follows a rigorous, non-destructive workflow that treats designs as read-only inputs.
- [COMMAND_EXECUTION]: Scripts provided for use with
execute_codeare limited to Penpot API interactions, such as shape creation, layout management, and metadata reading. These are necessary for the skill's stated purpose. - [DATA_EXFILTRATION]: There are no network-bound operations or access to sensitive local files (such as .env, .ssh, or cloud credentials). All data processing occurs within the Penpot workspace.
- [PROMPT_INJECTION]: The skill instructions do not contain any patterns attempting to bypass agent safeguards, override system behavior, or extract system prompts.
Audit Metadata