figma-motion-handoff
Warn
Audited by Snyk on Jul 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required workflow ingests Figma-derived “Dev Mode JSON” and MCP outputs via
get_design_context/get_motion_context(outsider-authored user-provided design data), which are readable text/structured content that the agent would place into the LLM context for translation.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata