figma-to-react-components
Pass
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill employs shell commands (Bash, Grep, Glob) for local project discovery, such as locating design token files and performing post-conversion cleanup. These operations are restricted to the project environment and support the core functionality.\n- [PROMPT_INJECTION]: No evidence of prompt injection, safety bypasses, or instruction overrides was found within the skill files or metadata.\n- [DATA_EXFILTRATION]: No unauthorized data harvesting or network exfiltration patterns were detected. All external data interaction is performed via the Figma MCP for design context extraction.\n- [REMOTE_CODE_EXECUTION]: No instances of remote code execution or installation of untrusted dependencies were identified. The skill references well-known, reputable packages such as react-aria.\n- [SAFE]: The skill follows a structured and secure workflow, emphasizing accessibility through React Aria and visual consistency through design tokens. No obfuscation or deceptive metadata was found.
Audit Metadata