figma-use-figjam
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions are focused strictly on operational tasks for FigJam. There are no patterns suggesting attempts to bypass safety filters, disregard prior instructions, or simulate unrestricted developer modes.
- [DATA_EXPOSURE_AND_EXFILTRATION]: No hardcoded credentials, API keys, or sensitive file paths (such as SSH keys or environment files) were found. Network interactions mentioned, such as asset uploads, are described as part of the official Figma MCP tool workflow and do not target untrusted domains.
- [OBFUSCATION]: The content was analyzed for Base64 encoding, zero-width characters, homoglyphs, and hidden text patterns (acrostics). All code and documentation are in plain, readable text.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of Figma node trees (via
get_figjam) to generate plugin code. While this represents a data ingestion surface, the skill provides specific recipes for handling node IDs and properties within the Figma sandbox, minimizing the risk of accidental instruction obedience from untrusted board content.
Audit Metadata