figma-reconciler

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is designed for read-only comparison tasks. It explicitly avoids modifications to code or design files and relies on standard MCP tools for Figma and browser interaction.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface through external sources. Ingestion points: Figma node metadata and variable definitions via get_metadata and get_variable_defs, and browser accessibility tree or DOM content. Boundary markers: None identified. Capability inventory: Reading Figma node data and performing browser measurements (computed styles, bounding rectangles). Sanitization: None specified for the data read from external sources. The risk is considered minimal as the skill's instructions focus on precise measurement and reporting for human verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:29 PM
Security Audit — agent-trust-hub — figma-reconciler