figma-rest-api-scrape

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell commands involving curl and jq to automate data retrieval from Figma's API. It also uses the macOS security utility to securely manage Personal Access Tokens (PATs) in the system keychain, which is a recommended security practice for CLI tools.
  • [EXTERNAL_DOWNLOADS]: The skill fetches design assets (PNG, SVG, PDF) from remote URLs provided by the Figma API. These URLs typically point to Amazon S3 buckets managed by Figma, which is standard and expected behavior for the skill's functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 06:02 AM
Security Audit — agent-trust-hub — figma-rest-api-scrape