figma-use-motion

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill suggests using the ffmpeg command-line tool to extract frames from exported MP4 files for local visual verification of animations.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves reading properties and metadata from Figma nodes, which serves as an ingestion point for untrusted data that could influence agent behavior.
  • Ingestion points: Figma node data retrieved via figma.currentPage.selection and figma.getNodeByIdAsync.
  • Boundary markers: There are no explicit boundary markers or instructions to ignore embedded content within node properties.
  • Capability inventory: The skill utilizes local shell command execution (ffmpeg) and write-access to the Figma Plugin API.
  • Sanitization: No sanitization, escaping, or validation of the ingested node data is implemented before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — figma-use-motion