design-to-code

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes design data and thumbnails from Figma to generate React code, which presents a surface for indirect prompt injection if the design content contains malicious instructions.
  • Ingestion points: Figma design JSON and thumbnail images fetched via the fetch-figma command.
  • Boundary markers: None explicitly defined in the manual instructions provided to the agent in SKILL.md.
  • Capability inventory: The skill has the capability to write generated code to the project's src/ directory using the save-code command.
  • Sanitization: No explicit sanitization or filtering of design content is performed in the provided helper script before passing data to the generation prompts.
  • [COMMAND_EXECUTION]: The workflow involves running a custom Node.js helper script (scripts/coderio-skill.mjs) that performs multiple file system operations, including creating directories, reading design protocols, and writing source code to the project workspace.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the coderio package from the NPM registry during the setup phase to provide the core design-to-code logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 01:54 PM
Security Audit — agent-trust-hub — design-to-code