figma-token-review
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Detailed technical review of the skill's 17 files confirms it functions as a legitimate design system utility. No evidence of prompt injection, data exfiltration, or obfuscation was found.
- [COMMAND_EXECUTION]: The skill automates design token validation by running local Node.js scripts (
evaluate.mjsandtypography-evaluate.mjs). These scripts operate on internal JSON data and do not interact with the network or sensitive system files. - [REMOTE_CODE_EXECUTION]: The skill leverages the
use_figmaplatform tool to execute a predefined, read-only extraction script (extract.figma.js). This script is used solely to gather design metadata for analysis and does not modify Figma files or execute untrusted external code.
Audit Metadata