design-tokens-extraction
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues or malicious patterns were detected in the skill's instructions or metadata. The skill focuses on standard design system automation workflows.
- [CREDENTIALS_UNSAFE]: The documentation includes instructions for users to verify their authentication environment variables (e.g.,
FIGMA_ACCESS_TOKEN). This represents safe and standard practice for local development tools rather than hardcoding sensitive credentials. - [PROMPT_INJECTION]: The skill processes data from external design sources via specialized tools. While this theoretically allows for indirect prompt injection if a design file contains malicious text, the structured extraction method via MCP servers significantly reduces the attack surface compared to raw text ingestion.
Audit Metadata