figma-make-exporter

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands such as node, mkdir, and cp. These commands are used to invoke a local utility script (scripts/canvas-fig-sync.mjs) for project maintenance tasks like packing assets, inspecting files, and generating manifests. These operations are aligned with the skill's stated purpose of managing project exports.
  • [EXTERNAL_DOWNLOADS]: The skill references a relative API path /api/export-make, which is described as a backend interface for the Axhub platform's export functionality. There are no references to external, untrusted domains or remote script downloads.
  • [PROMPT_INJECTION]: The instructions focus entirely on project structure, asset management, and technical workflows. No patterns attempting to bypass safety filters, override agent identity, or extract system prompts were found.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 06:31 AM
Security Audit — agent-trust-hub — figma-make-exporter