figma-generate-diagram
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by design. It instructs the agent to ingest untrusted data from various external sources to inform the diagram generation process.
- Ingestion points: The instructions in
SKILL.md(Step 4) encourage the agent to gather context from source code, user-provided documents (PRDs, specs, meeting notes), and other external tools like issue trackers or wikis. - Boundary markers: There are no specific instructions or boundary markers defined to prevent the agent from following malicious instructions that might be embedded within these external data sources.
- Capability inventory: The agent has access to the
generate_diagramtool to render content and theuse_figmatool, which can modify FigJam boards by adding shapes, text, and connectors, potentially allowing an injection to manipulate the user's workspace. - Sanitization: The skill does not prescribe any sanitization or validation logic for the external content before it is interpolated into prompts for Mermaid syntax generation or Figma board modifications.
Audit Metadata