figma-automation
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill's functionality is limited to guiding the agent through existing tool sequences for Figma automation via the Rube MCP protocol.
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to configure the Rube MCP server using the URL
https://rube.app/mcp. This is a legitimate reference for the skill's primary purpose and does not involve silent or unauthorized background downloads. - [COMMAND_EXECUTION]: The documentation references various Figma tools (e.g.,
FIGMA_GET_FILE_JSON,FIGMA_RENDER_IMAGES_OF_FILE_NODES). These are platform-specific tool calls for interacting with the Figma API and do not involve arbitrary shell command execution or system-level modifications. - [PROMPT_INJECTION]: The skill uses clear, procedural language to define task triggers and boundaries. No attempts to bypass safety filters, override system instructions, or extract system prompts were observed.
Audit Metadata