skills/cursor/plugins/build-figma/Gen Agent Trust Hub

build-figma

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted design data from external Figma files, creating a potential surface for indirect instructions. 1. Ingestion points: Figma design context and brand assets from external figma.com URLs. 2. Boundary markers: No specific delimiters or safety warnings are used to separate Figma metadata from agent instructions. 3. Capability inventory: File system writing to /tmp and UI control via vendor-specific tools. 4. Sanitization: No explicit sanitization or validation of node names or design metadata is described before processing.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves brand assets from external URLs provided by the Figma MCP plugin to ensure design fidelity. These downloads are part of the core functionality and involve a well-known design platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 01:00 AM
Security Audit — agent-trust-hub — build-figma