figma-generate-design

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and interpret external source code and web application data, creating an indirect prompt injection surface. Malicious instructions or adversarial patterns embedded in the processed source files could attempt to influence the agent's design generation logic.
  • Ingestion points: Project source code files (Step 2a-i) and web application URLs (Step 1.5, Parallel Workflow).
  • Boundary markers: None specified in the instructions to separate untrusted data from agent instructions.
  • Capability inventory: The agent has extensive control over Figma documents via the use_figma tool, including creating, deleting, and modifying design nodes.
  • Sanitization: No sanitization or filtering logic is provided for the ingested code content.
  • [COMMAND_EXECUTION]: The skill generates and executes JavaScript snippets using the use_figma tool. This functionality is the primary intended mechanism for interacting with the Figma Plugin API and is scoped to the Figma environment.
  • [EXTERNAL_DOWNLOADS]: The skill uses the generate_figma_design tool to fetch data and capture screenshots from external web applications. These operations are user-directed for legitimate design reference and visual validation purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:29 PM
Security Audit — agent-trust-hub — figma-generate-design