figma-generate-library
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface (Category 8) during its discovery phase.
- Ingestion points: The agent is instructed to read and analyze various files from the user's local codebase, including
*.tokens.json,*.css, andtailwind.config.js, as detailed inreferences/discovery-phase.md. - Boundary markers: The instructions do not specify explicit delimiters or 'ignore' instructions for the data being processed to prevent the agent from obeying instructions hidden within the code files.
- Capability inventory: The skill has extensive mutation privileges via
use_figma, allowing it to create, modify, and delete Figma pages, components, and variables. - Sanitization: The skill uses regex-based extraction for tokens, which mitigates some risk but does not fully neutralize the potential for instruction injection in free-text fields or complex JSON structures.
- [COMMAND_EXECUTION]: The skill uses the
use_figmatool to execute dynamically generated JavaScript. While the core logic is provided in thescripts/directory, these scripts perform heavy mutations on the Figma document. Thescripts/cleanupOrphans.jsfile specifically allows for the bulk deletion of Figma nodes based on metadata tags and run IDs.
Audit Metadata