figma-generate-diagram

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely composed of instructional markdown and configuration for the generate_diagram tool. No executable code or suspicious shell commands were found.- [SAFE]: The skill uses official Figma tools (get_figjam, get_design_context, use_figma) and references legitimate figma.com domains, aligning with the figma author context.- [SAFE]: No hardcoded credentials, API keys, or sensitive environment variable access patterns were detected.- [SAFE]: No remote downloads, package installations, or dynamic code execution patterns are present. All diagram rendering is handled through the platform's native tool.- [SAFE]: The skill includes a Step 4 (Garbage in, garbage out) that encourages gathering context from source code and user documents. While this is an ingestion point for external data (Category 8: Indirect Prompt Injection), the capabilities are restricted to generating Mermaid syntax for visual diagrams, presenting no significant risk of privilege escalation or exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 01:25 AM