prototype-to-figma
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill generates and executes JavaScript code at runtime using the
use_figmatool. It utilizes structural templates provided infigma-patterns.mdto programmatically build design frames and components based on the analysis of a working prototype. - [PROMPT_INJECTION]: The skill ingests and processes untrusted data from local source files (such as React components and CSS). This functionality creates an indirect prompt injection surface where instructions embedded in the source code (e.g., within comments) could potentially be interpreted by the agent to deviate from its intended design task.
Audit Metadata