pencil-design-bridge
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill includes explicit instructions to prevent the storage of sensitive data such as API keys, tokens, or private credentials in design handoff files.
- [COMMAND_EXECUTION]: The SKILL.md file documents a validation process involving the execution of local Python scripts for linting and schema verification, using environment variables to locate the tools.
- [SAFE]: Access to .pen design files is restricted to specific MCP tools, explicitly forbidding the use of standard shell commands like cat or grep to ensure artifact integrity.
- [PROMPT_INJECTION]: The skill ingests design briefs, representing an indirect prompt injection surface. Ingestion points include the 'brief' and 'review-output' modes in SKILL.md. Boundary markers are established via the references/pencil-bridge-contract.md and the mandatory confirmation of approval by the senior-ui-ux-orchestrator agent. Capability inventory is limited to design tool interactions and local validation scripts. Sanitization is managed through manual workflow checkpoints that verify source authority.
Audit Metadata