figma-to-code

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a platform-specific feature to execute an 'ls' command on startup to verify the presence of recommended companion skills in local and global directories. This is used for environment assessment and dependency management.
  • [EXTERNAL_DOWNLOADS]: The skill documentation recommends installing related design utilities from the AbsolutelySkilled vendor repository. These commands use standard 'npx' execution which is typical for the intended environment.
  • [SAFE]: The skill processes UI design specifications. While this represents a surface for indirect prompt injection, no exploitable capabilities or unsafe interpolation patterns were found. Ingestion points: Figma designs/specs in SKILL.md; Boundary markers: Absent; Capability inventory: No dangerous commands or execution flows identified; Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 06:19 PM
Security Audit — agent-trust-hub — figma-to-code