figma
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: Provides automated scripts using
curl,jq, andbunfor interacting with the Figma API and managing local design assets. - [EXTERNAL_DOWNLOADS]: Recommends the installation of
@figma-export/cliand its plugins from the npm registry to handle component exports. - [INDIRECT_PROMPT_INJECTION]: The skill fetches node data from the Figma API (an external source) and transmits it to an LLM (
gemini -m pro) for code generation, creating a potential attack surface if design content or metadata contains adversarial instructions intended to influence the AI's output. - [DYNAMIC_EXECUTION]: Employs an AI model to dynamically generate React component code and styles based on design data retrieved from Figma at runtime.
Audit Metadata