figma-make-project-converter

Warn

Audited by Snyk on May 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's workflow requires feeding a user-provided Figma Make export (the ZIP/unpacked project directory) into the converter script (see "步骤 1:运行预处理脚本" and the listed files like DESIGN_SYSTEM_GUIDE.md, TOKEN_REFERENCE.md, ai_chat.json and other project files), and the AI analysis step explicitly reads and analyzes those untrusted, user-generated project files to generate reports and conversion actions, which could allow indirect prompt injection via crafted project documents.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 20, 2026, 06:30 AM
Issues
1
Security Audit — snyk — figma-make-project-converter