pixel-audit
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exposes an indirect prompt injection attack surface because it ingests design metadata from external design tools and uses browser automation tools to verify styles.\n
- Ingestion points: Design metadata and variables are retrieved from Figma MCP nodes in Step 3 of the audit process and referenced in the evidence capture guidelines.\n
- Boundary markers: The skill lacks explicit delimiters or specific instructions for the agent to disregard any embedded directives that might be present in the imported Figma metadata.\n
- Capability inventory: The skill is authorized to evaluate JavaScript within a browser environment (
getBoundingClientRect,getComputedStyle), perform file system operations to log defects, and usecurlto verify asset pipelines.\n - Sanitization: There is no mention of sanitizing or validating the contents of the Figma node metadata before it is utilized in the verification and fixing stages.
Audit Metadata