sb-figma

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes Node.js and Python scripts for design data processing, implementing security best practices such as file path sanitization and atomic file writes.
  • [COMMAND_EXECUTION]: Executes bundled scripts using node and python3 to normalize Figma variables, check token parity, and record component deliveries.
  • [EXTERNAL_DOWNLOADS]: Connects to Figma via the Model Context Protocol (MCP) to ingest design tokens and component metadata, which is an expected and necessary function for the skill's purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 01:16 PM
Security Audit — agent-trust-hub — sb-figma