figma
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Figma REST API and external connectors, which could contain malicious instructions.
- Ingestion points: Node trees, variables, and metadata fetched from figma.com URLs or the Figma API in multiple phases (Asset, Tokens, Component).
- Boundary markers: The instructions do not define explicit delimiters or warnings for the agent to ignore instructions embedded in the design data.
- Capability inventory: The skill can execute shell commands via
npxand a local Node.js script (scripts/verify-motion.mjs) which callsffmpegandffprobe. - Sanitization: The documentation notes that SVG assets are sanitized during the import process.
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npxto fetch and update thehyperframesCLI tool from the npm registry as part of its setup and maintenance workflow. - [COMMAND_EXECUTION]: A bundled script,
scripts/verify-motion.mjs, usesexecFileSyncandspawnSyncto perform video analysis. While it processes file paths provided as arguments, it uses secure argument passing (arrays) to prevent shell-based command injection.
Audit Metadata