@tank/figma-plugin
Pass
Audited by Gen Agent Trust Hub on May 31, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The manifest file
tank.jsonrequestssubprocess: trueand broad filesystem read/write permissions for all paths (**/*). This allows the agent to execute shell commands and modify local files, which is necessary for creating and building Figma plugin projects as described in the skill content. - [PROMPT_INJECTION]: Instructional text in
SKILL.mdand reference files uses formatting markers such as 'CRITICAL' and 'IMPORTANT' for technical emphasis (e.g., regarding API constraints and font loading). These were analyzed and found to be benign, and do not represent attempts to bypass agent safety guidelines. - [SAFE]: No outbound network permissions are requested in the manifest, and no suspicious obfuscation or remote code execution patterns were detected in the skill instructions or metadata.
Audit Metadata