figma
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEPERSISTENCEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill is configured to connect to the official Figma MCP server at
https://mcp.figma.com/mcp. This is a well-known service and the connection is a requirement for the skill's primary functionality. - [PERSISTENCE]: In
references/figma-mcp-config.md, the skill provides instructions for persisting theFIGMA_OAUTH_TOKENby adding export commands to shell profiles like~/.bashrcor~/.zshrc. While this is a standard method for managing development environment variables, it involves modifying files that govern shell persistence. - [INDIRECT_PROMPT_INJECTION]: The skill features an indirect prompt injection surface because it ingests external design data to drive code implementation decisions.
- Ingestion points: Untrusted design data enters the agent's context through tools like
get_design_contextandget_metadatadescribed inSKILL.mdandreferences/figma-tools-and-prompts.md. - Boundary markers: There are no explicit instructions for the agent to use delimiters or ignore potentially malicious instructions embedded within the Figma node data.
- Capability inventory: The agent is instructed to translate design data into production-ready React and Tailwind code, which involves file-writing capabilities in the user's project.
- Sanitization: The skill lacks defined validation or sanitization protocols for the structured design representation fetched from the Figma API.
Audit Metadata