design-handoff
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- External Data Ingestion Surface: The skill is designed to process external content from Figma URLs or design descriptions, which introduces a potential surface for indirect prompt injection.
- Ingestion points: External data enters the agent context through the
$ARGUMENTSand@$1variables inSKILL.md. - Boundary markers: The instructions do not define explicit delimiters or instructions to ignore embedded commands within the ingested design data.
- Capability inventory: The skill produces detailed specifications and references integrations with design tools and project trackers.
- Sanitization: There are no specified mechanisms for sanitizing or validating the external input before it is interpreted.
Audit Metadata