journey
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses Model Context Protocol (MCP) tools, such as
mcp__claude_ai_Figma__use_figmaandmcp__pencil__batch_design, to facilitate diagram creation in external design applications. These are intended uses of the platform's tool capabilities. - [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by interpolating user-supplied data into its visual outputs.
- Ingestion points: User descriptions of design flows provided at runtime.
- Boundary markers: The generated HTML artifacts are bounded by markdown code blocks.
- Capability inventory: The skill leverages authorized MCP design tools and static code generation.
- Sanitization: There is no explicit sanitization for user-provided labels, though the risk is minimal given the static and visual nature of the output.
Audit Metadata