figma
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
- [PERSISTENCE_MECHANISMS]: The reference documentation in
references/figma-mcp-config.mdinstructs users to persist theFIGMA_OAUTH_TOKENby adding export commands to shell profiles like~/.zshrcor~/.bashrc. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill manages a sensitive
FIGMA_OAUTH_TOKENand connects to a remote Figma MCP server athttps://mcp.figma.com/mcp, which is recognized as a well-known and trusted service. - [INDIRECT_PROMPT_INJECTION]: The skill retrieves design context and metadata from the external Figma API to generate production code, creating a surface where malicious instructions could potentially be embedded in design nodes.
- Ingestion points: Untrusted data enters the agent context via the
get_design_contextandget_metadatatools frommcp.figma.com(noted inSKILL.mdandreferences/figma-tools-and-prompts.md). - Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are used when processing the external design data.
- Capability inventory: The agent has the capability to generate and implement code changes in the project repository based on the fetched data.
- Sanitization: There is no evidence of sanitization or validation of the retrieved design data before it is used to drive code generation.
Audit Metadata