figma-generate-library

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface (Category 8) during its discovery phase.
  • Ingestion points: The agent is instructed to read and analyze various files from the user's local codebase, including *.tokens.json, *.css, and tailwind.config.js, as detailed in references/discovery-phase.md.
  • Boundary markers: The instructions do not specify explicit delimiters or 'ignore' instructions for the data being processed to prevent the agent from obeying instructions hidden within the code files.
  • Capability inventory: The skill has extensive mutation privileges via use_figma, allowing it to create, modify, and delete Figma pages, components, and variables.
  • Sanitization: The skill uses regex-based extraction for tokens, which mitigates some risk but does not fully neutralize the potential for instruction injection in free-text fields or complex JSON structures.
  • [COMMAND_EXECUTION]: The skill uses the use_figma tool to execute dynamically generated JavaScript. While the core logic is provided in the scripts/ directory, these scripts perform heavy mutations on the Figma document. The scripts/cleanupOrphans.js file specifically allows for the bulk deletion of Figma nodes based on metadata tags and run IDs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:29 PM
Security Audit — agent-trust-hub — figma-generate-library