penpot-foundations

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates entirely within the Penpot environment, using the legitimate penpot and penpotUtils APIs to manage tokens and design elements.\n- [SAFE]: No external network communication, data exfiltration, or credential harvesting was detected. The skill correctly instructs users to manage secrets in standard ways if needed, though none are required for this specific tool.\n- [SAFE]: The scripts provided for token creation and application (createTokenSet.js, applyTokensToShapes.js, etc.) follow idempotent patterns, checking for existing entities before modification to prevent design corruption.\n- [SAFE]: The skill uses execute_code as its primary mechanism for interacting with Penpot, which is the intended and standard execution model for this agent's capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 01:09 PM
Security Audit — agent-trust-hub — penpot-foundations