skills/adobe/skills/figma-to-content/Gen Agent Trust Hub

figma-to-content

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill orchestrates multiple Adobe-authored skills and interacts exclusively with official Adobe domains (da.live, hlx.page, aem.page) for content authoring and deployment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted Figma design data but mitigates risks through explicit sanitization rules in Phase 4 and Guardrails, including HTML-escaping all design-derived strings and validating URL schemes for links.
  • [SAFE]: Implements a 'Preflight' phase (Phase 0) to verify prerequisites like Figma MCP connectivity and DA token availability before starting any migration operations.
  • [SAFE]: Employs a 'Plan Confirmation' step (Phase 2.2) that requires the agent to present the intended mapping to the user for approval before any code is pushed or content is deployed.
  • [SAFE]: Features an 'Overwrite Guard' (Phase 5) that checks for the existence of the target page and requires explicit user confirmation before overwriting any existing content.
  • [PROMPT_INJECTION]: The detection of prompt injection patterns in references/annotation-contract.md is a false positive; the instructions specifically direct the agent to treat external data as content rather than commands, which is a defensive security measure.
  • [SAFE]: No hardcoded credentials, malicious obfuscation, or unauthorized remote code execution patterns were identified within the skill's scripts or instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 03:48 PM
Security Audit — agent-trust-hub — figma-to-content