token-map
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests design token data from external sources, which represents an indirect prompt injection surface.
- Ingestion points: The skill reads
figma/tokens.jsonandcode/tokens.jsonas primary inputs (SKILL.md). - Boundary markers: The instructions provide clear boundaries by stating the agent must not "invent target tokens silently" and must use
unmatched.jsonfor human auditing. - Capability inventory: The skill is capable of writing multiple JSON files to the local
project-cwd/token-map/directory. - Sanitization: The skill employs semantic role inference and evidence-based mapping logic to validate the role of anonymous tokens before they are accepted into the target system.
- [SAFE]: The skill is authored by Open Design and its external references point to official vendor infrastructure on GitHub (
github.com/nexu-io). No unauthorized network access, credential exposure, or persistence mechanisms were detected. The file system operations are localized to the design migration task.
Audit Metadata