figma-prod-checklist
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [SAFE]: The skill provides guidelines and snippets for auditing Figma integrations for production fitness. It references resources from the author's official domains (jeremylongshore.com, intentsolutions.io) and project sites (tonsofskills.com), which are consistent with the vendor's provided metadata.
- [COMMAND_EXECUTION]: Includes Bash snippets for verifying Figma API connectivity and status. These snippets use official Figma domains (api.figma.com, www.figmastatus.com) and are consistent with the skill's stated purpose.
- [CREDENTIALS_UNSAFE]: The skill references authentication tokens via environment variables (FIGMA_PAT). It adheres to security best practices by recommending the use of secret managers and prohibiting token storage in source code or client-side environments.
Audit Metadata