figma-use-motion
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill suggests using the ffmpeg command-line tool to extract frames from exported MP4 files for local visual verification of animations.
- [INDIRECT_PROMPT_INJECTION]: The skill involves reading properties and metadata from Figma nodes, which serves as an ingestion point for untrusted data that could influence agent behavior.
- Ingestion points: Figma node data retrieved via figma.currentPage.selection and figma.getNodeByIdAsync.
- Boundary markers: There are no explicit boundary markers or instructions to ignore embedded content within node properties.
- Capability inventory: The skill utilizes local shell command execution (ffmpeg) and write-access to the Figma Plugin API.
- Sanitization: No sanitization, escaping, or validation of the ingested node data is implemented before processing.
Audit Metadata