figma-use-slides
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and process content from existing Figma files, which serves as an entry point for untrusted data that could contain adversarial instructions.
- Ingestion points: The skill utilizes read-only scripts to extract slide text, speaker notes, and structural layout information using the
figmaglobal object (e.g.,figma.getSlideGrid()inreferences/slide-grid.mdandslide.findAllWithCriteriainSKILL.md). - Boundary markers: There are no instructions for the agent to use specific delimiters or to disregard embedded instructions when processing content retrieved from Figma slides.
- Capability inventory: The agent uses the
use_figmatool to execute generated JavaScript in the Figma environment andupload_assetsfor network-based image uploads, providing a wide range of actions that could be targeted by an injection. - Sanitization: The instructions do not prescribe any filtering, validation, or escaping of the ingested text before it is used for design planning or subsequent code generation.
- [DYNAMIC_EXECUTION]: The skill revolves around the runtime generation and execution of JavaScript code to interact with the Figma Plugin API. While this is the intended purpose, it constitutes a powerful capability for dynamic code execution.
- Evidence: The
Buildphase inSKILL.mdand various examples in thereferences/folder provide templates for the agent to assemble complex scripts that are executed via theuse_figmaMCP tool.
Audit Metadata