figma-portfolio-nextjs

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to clone source code from a personal GitHub repository (github.com/ibrahimmemonn/Figma_Portfolio).\n- [COMMAND_EXECUTION]: The installation process requires running npm install and npm run dev on the cloned repository, which leads to the execution of code within the agent's environment.\n- [REMOTE_CODE_EXECUTION]: By combining a repository clone with npm install, the skill enables the execution of remote code from an unverified source.\n- [EXTERNAL_DOWNLOADS]: The skill integrates the @vercel/analytics package from Vercel's trusted infrastructure.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 12:47 PM
Security Audit — agent-trust-hub — figma-portfolio-nextjs