figma-generate-diagram
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely composed of instructional markdown and configuration for the generate_diagram tool. No executable code or suspicious shell commands were found.- [SAFE]: The skill uses official Figma tools (get_figjam, get_design_context, use_figma) and references legitimate figma.com domains, aligning with the figma author context.- [SAFE]: No hardcoded credentials, API keys, or sensitive environment variable access patterns were detected.- [SAFE]: No remote downloads, package installations, or dynamic code execution patterns are present. All diagram rendering is handled through the platform's native tool.- [SAFE]: The skill includes a Step 4 (Garbage in, garbage out) that encourages gathering context from source code and user documents. While this is an ingestion point for external data (Category 8: Indirect Prompt Injection), the capabilities are restricted to generating Mermaid syntax for visual diagrams, presenting no significant risk of privilege escalation or exfiltration.
Audit Metadata