figma-automation

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill's functionality is limited to guiding the agent through existing tool sequences for Figma automation via the Rube MCP protocol.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to configure the Rube MCP server using the URL https://rube.app/mcp. This is a legitimate reference for the skill's primary purpose and does not involve silent or unauthorized background downloads.
  • [COMMAND_EXECUTION]: The documentation references various Figma tools (e.g., FIGMA_GET_FILE_JSON, FIGMA_RENDER_IMAGES_OF_FILE_NODES). These are platform-specific tool calls for interacting with the Figma API and do not involve arbitrary shell command execution or system-level modifications.
  • [PROMPT_INJECTION]: The skill uses clear, procedural language to define task triggers and boundaries. No attempts to bypass safety filters, override system instructions, or extract system prompts were observed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 11:32 AM
Security Audit — agent-trust-hub — figma-automation