prototype-to-figma

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill generates and executes JavaScript code at runtime using the use_figma tool. It utilizes structural templates provided in figma-patterns.md to programmatically build design frames and components based on the analysis of a working prototype.
  • [PROMPT_INJECTION]: The skill ingests and processes untrusted data from local source files (such as React components and CSS). This functionality creates an indirect prompt injection surface where instructions embedded in the source code (e.g., within comments) could potentially be interpreted by the agent to deviate from its intended design task.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 07:49 PM
Security Audit — agent-trust-hub — prototype-to-figma