figma

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate instructions for setting up and using the Figma MCP server. The FIGMA_OAUTH_TOKEN environment variable is a standard practice for managing access to the Figma API. The external URL https://mcp.figma.com/mcp is an official Figma endpoint, and the instructions follow best practices for secure secret management by advising users to store tokens in environment variables or shell profiles rather than hardcoding them. No malicious patterns, obfuscation, or unauthorized data access were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:56 PM
Security Audit — agent-trust-hub — figma