figma-use-motion
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No evidence of prompt injection attempts or bypass instructions were found in the skill or its reference documents.
- [DATA_EXFILTRATION]: The skill does not access sensitive local files or perform unauthorized network requests. It uses official Figma Plugin API methods and tools for its intended purpose of design and animation.
- [REMOTE_CODE_EXECUTION]: No patterns of downloading or executing untrusted code were identified. The skill generates code snippets for the
use_figmatool, which is the primary intended function of the skill. - [COMMAND_EXECUTION]: The skill mentions the use of
ffmpegfor frame extraction if available on the local system, which is a common utility for motion designers and is used here in a legitimate context. - [INDIRECT_PROMPT_INJECTION]: While the skill processes data from Figma nodes (such as names and properties) which could theoretically contain malicious text, it does not demonstrate exploitable patterns, and the risk is considered low and inherent to the tool's purpose.
Audit Metadata