figma-automation

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructions for interacting with the Figma API via the Rube MCP server. All tools (e.g., FIGMA_GET_FILE_JSON, FIGMA_RENDER_IMAGES_OF_FILE_NODES) and workflows (authentication, resource discovery) are consistent with legitimate design automation use cases.
  • [EXTERNAL_DOWNLOADS]: The skill directs users to add https://rube.app/mcp as an MCP server. This is a well-known service for AI agent toolkits and does not involve the execution of untrusted scripts or the download of malicious binaries.
  • [COMMAND_EXECUTION]: The skill documentation describes tool sequences for interacting with the Figma API. It does not instruct the agent to execute shell commands, manage processes, or perform any dangerous system-level operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 03:04 PM
Security Audit — agent-trust-hub — figma-automation