Framer Expert
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill integrates with external Framer projects and CMS content via the Model Context Protocol (MCP), which creates an attack surface for indirect prompt injection where malicious instructions hidden in external data could influence agent behavior.
- Ingestion points: Accesses Framer project structures, components, and CMS content via MCP tools as described in SKILL.md.
- Boundary markers: The instructions lack explicit delimiters or 'ignore instructions' directives for the content retrieved from external sources.
- Capability inventory: The skill allows the agent to generate code, documentation, and project analyses based on the retrieved data.
- Sanitization: No specific content validation or sanitization logic is provided in the skill instructions to mitigate the risk of processing malicious data.
Audit Metadata