color-token-format-normalizer

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: No malicious behavior or suspicious instructions were found in the skill content. The stated purpose of color token normalization aligns with the instructions provided.
  • [NO_CODE]: The skill does not contain any executable scripts or binary files, which significantly reduces its attack surface.
  • [PROMPT_INJECTION]: The skill processes external data from user code and Figma contexts, representing a potential injection surface. The risk is negligible as the skill lacks high-risk capabilities like network access or shell execution. * Ingestion points: User-provided code snippets and Figma design elements (layers, components, styles). * Boundary markers: Not explicitly defined for input sanitization. * Capability inventory: Operations are restricted to analysis and scoped design-file edits within the Figma environment; no network or shell capabilities are present. * Sanitization: No specific sanitization or filtering of input data is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:31 AM
Security Audit — agent-trust-hub — color-token-format-normalizer