Third-party audit

Gen Agent Trust Hub

napkin · github/awesome-copilot

Passed
Provider summary

The 'napkin' skill provides a visual whiteboard for Copilot CLI. It operates by opening a local HTML file and interpreting user sketches via screenshots and clipboard data. The primary security considerations include the use of system commands to access the clipboard and the potential for indirect prompt injection from content drawn or written on the whiteboard.

The provider classified the analyzed snapshot as NONE risk. This result applies to the content available at audit time.

Provider
Gen Agent Trust Hub
Normalized result
pass
Risk level
NONE
Audited
Mar 09, 2026
Interpretation

How to use this signal

01

Confirm the source

Compare the repository, publisher, and installation command before continuing.

02

Read the content

Review SKILL.md, scripts, and allowed tools. Artificial Atlas never executes them during indexing.

03

Limit permissions

Use the narrowest possible scope and avoid broad credentials for third-party skills.