figma-extract

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Figma (node trees, design tokens, and text content), which creates an attack surface for indirect prompt injection if the design file contains malicious instructions designed to influence the agent.
  • Ingestion points: Data is ingested from Figma file URLs and node IDs via the Figma REST API or an MCP server.
  • Boundary markers: The skill description does not specify the use of delimiters or 'ignore' instructions to isolate the Figma data from the agent's core logic.
  • Capability inventory: The skill has the capability to write multiple files (JSON and binary assets) to the project's current working directory.
  • Sanitization: There are no documented steps for sanitizing the text or metadata fetched from Figma before it is written to the filesystem or passed to downstream tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 01:19 PM
Security Audit — agent-trust-hub — figma-extract