skills/hk-hub/agentskills/figma/Gen Agent Trust Hub

figma

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
  • [PERSISTENCE_MECHANISMS]: The reference documentation in references/figma-mcp-config.md instructs users to persist the FIGMA_OAUTH_TOKEN by adding export commands to shell profiles like ~/.zshrc or ~/.bashrc.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill manages a sensitive FIGMA_OAUTH_TOKEN and connects to a remote Figma MCP server at https://mcp.figma.com/mcp, which is recognized as a well-known and trusted service.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves design context and metadata from the external Figma API to generate production code, creating a surface where malicious instructions could potentially be embedded in design nodes.
  • Ingestion points: Untrusted data enters the agent context via the get_design_context and get_metadata tools from mcp.figma.com (noted in SKILL.md and references/figma-tools-and-prompts.md).
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are used when processing the external design data.
  • Capability inventory: The agent has the capability to generate and implement code changes in the project repository based on the fetched data.
  • Sanitization: There is no evidence of sanitization or validation of the retrieved design data before it is used to drive code generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:31 PM
Security Audit — agent-trust-hub — figma