skills/hk-hub/agentskills/figma-use/Gen Agent Trust Hub

figma-use

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates reading data from Figma files (such as layer names and text content), which acts as an entry point for external, potentially untrusted data. The documentation mitigates this risk by recommending incremental verification and using structured return values to keep the agent oriented.\n
  • Ingestion points: Figma node metadata, names, and characters accessed via read-only tool calls (e.g., in SKILL.md and references/common-patterns.md).\n
  • Boundary markers: None explicitly defined for untrusted data, though the skill mandates returning structured node IDs to maintain execution state.\n
  • Capability inventory: Extensive access to the Figma Plugin API for creating, editing, and deleting canvas elements, variables, and styles.\n
  • Sanitization: Reference snippets do not include explicit sanitization for ingested strings before using them in subsequent operations.\n- [DYNAMIC_EXECUTION]: The primary purpose of the skill is to guide the agent in generating and executing JavaScript code within the Figma Plugin environment. The instructions include a robust 'Pre-Flight Checklist' and error recovery patterns (such as atomicity of scripts) to ensure that code execution is predictable and safe.\n
  • Execution method: The use_figma tool executes generated JavaScript in a wrapped async context.\n
  • Safety measures: Explicit rules against high-risk or unimplemented APIs (e.g., figma.notify), mandatory font loading to prevent runtime errors, and guidance to perform multi-page operations in parallel for consistent state management.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — figma-use