design-tokens-extraction

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues or malicious patterns were detected in the skill's instructions or metadata. The skill focuses on standard design system automation workflows.
  • [CREDENTIALS_UNSAFE]: The documentation includes instructions for users to verify their authentication environment variables (e.g., FIGMA_ACCESS_TOKEN). This represents safe and standard practice for local development tools rather than hardcoding sensitive credentials.
  • [PROMPT_INJECTION]: The skill processes data from external design sources via specialized tools. While this theoretically allows for indirect prompt injection if a design file contains malicious text, the structured extraction method via MCP servers significantly reduces the attack surface compared to raw text ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 07:18 AM
Security Audit — agent-trust-hub — design-tokens-extraction