figma-craft

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill provides a JavaScript audit tool in 'references/audit-layout.md' for use with the Figma Plugin API. The script is designed for read-only property inspection (checking node dimensions and auto-layout settings) to catch design errors without modifying the document or performing unauthorized network activity.- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external Figma files and design systems, creating a potential surface for indirect injection. The skill mitigates this through a structured workflow: 1) Ingestion points: Figma node data and design system tokens. 2) Boundary markers: Requirement to define the layout tree in text before executing commands. 3) Capability inventory: Layout manipulation via the 'use_figma' tool. 4) Sanitization: Mandatory verification using property assertions and server-side screenshots to confirm the agent's actions align with the user's intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 12:12 PM
Security Audit — agent-trust-hub — figma-craft