figma-use-slides

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and process content from existing Figma files, which serves as an entry point for untrusted data that could contain adversarial instructions.
  • Ingestion points: The skill utilizes read-only scripts to extract slide text, speaker notes, and structural layout information using the figma global object (e.g., figma.getSlideGrid() in references/slide-grid.md and slide.findAllWithCriteria in SKILL.md).
  • Boundary markers: There are no instructions for the agent to use specific delimiters or to disregard embedded instructions when processing content retrieved from Figma slides.
  • Capability inventory: The agent uses the use_figma tool to execute generated JavaScript in the Figma environment and upload_assets for network-based image uploads, providing a wide range of actions that could be targeted by an injection.
  • Sanitization: The instructions do not prescribe any filtering, validation, or escaping of the ingested text before it is used for design planning or subsequent code generation.
  • [DYNAMIC_EXECUTION]: The skill revolves around the runtime generation and execution of JavaScript code to interact with the Figma Plugin API. While this is the intended purpose, it constitutes a powerful capability for dynamic code execution.
  • Evidence: The Build phase in SKILL.md and various examples in the references/ folder provide templates for the agent to assemble complex scripts that are executed via the use_figma MCP tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — figma-use-slides