penpot-router
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill focuses on intent classification and routing, using read-only calls to the
execute_codetool for analyzing file structure, selection, and tokens without modifying the canvas. - [SAFE]: The discovery mechanism incorporates specific, hardcoded JavaScript snippets for state sensing, which are restricted to observing page names, selection counts, and token presence.
- [SAFE]: State management is correctly implemented using standard Penpot API features such as
setSharedPluginDataand session-based storage, intended for maintaining context across agent runs. - [SAFE]: No remote code execution patterns, external network requests, or unauthorized dependency installations were identified in the skill instructions or supporting files.
Audit Metadata