figma-make-exporter
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands such as
node,mkdir, andcp. These commands are used to invoke a local utility script (scripts/canvas-fig-sync.mjs) for project maintenance tasks like packing assets, inspecting files, and generating manifests. These operations are aligned with the skill's stated purpose of managing project exports. - [EXTERNAL_DOWNLOADS]: The skill references a relative API path
/api/export-make, which is described as a backend interface for the Axhub platform's export functionality. There are no references to external, untrusted domains or remote script downloads. - [PROMPT_INJECTION]: The instructions focus entirely on project structure, asset management, and technical workflows. No patterns attempting to bypass safety filters, override agent identity, or extract system prompts were found.
Audit Metadata