figma
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides secure guidance for managing Figma access tokens, instructing users to use environment variables or .env files and explicitly warning against sharing tokens in the conversation.
- [COMMAND_EXECUTION]: The skill uses the hyperframes CLI for asset management and token retrieval. A provided Node.js script (verify-motion.mjs) uses ffmpeg and ffprobe for motion verification, with input validation and safe process execution to prevent command injection.
- [EXTERNAL_DOWNLOADS]: The skill references standard updates via npx and the use of well-known animation libraries (GSAP) from public CDNs, which is consistent with its stated purpose and the trusted nature of the vendor.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external Figma URLs and IDs (ingestion points) using a specialized parser (boundary markers). Capabilities include CLI-driven file writes and API calls, with input validation performed by the underlying toolset (sanitization).
- [DATA_EXFILTRATION]: The skill includes anonymous, consent-gated usage beacons to track success and error rates, which is a standard telemetry practice and does not involve sensitive data.
Audit Metadata