figma-pilot-mcp

Warn

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires installing an MCP server via 'npx @youware-labs/figma-pilot-mcp', which downloads code from an external, non-verified organization.
  • [EXTERNAL_DOWNLOADS]: Users are instructed to download a plugin ZIP file from a GitHub repository ('github.com/youware-labs/figma-pilot/releases') not included in the verified list.
  • [COMMAND_EXECUTION]: The 'figma_execute' tool allows the agent to execute arbitrary JavaScript code within the Figma environment, creating a high-privilege execution primitive.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by reading Figma data that could contain malicious instructions. Ingestion points: figma.query() calls in SKILL.md. Boundary markers: None. Capability inventory: figma.create, figma.modify, figma.delete, figma.export. Sanitization: None.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 15, 2026, 12:04 PM
Security Audit — agent-trust-hub — figma-pilot-mcp