figma-developer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted design metadata and assets (component names, descriptions, styles, and SVG content) from the Figma API and incorporates them into generated React components, CSS, and TypeScript files. A compromised or malicious Figma file could theoretically influence the generated code or styles.
  • Ingestion points: Data is fetched via api.getFile, api.getImages, and fetch from the Figma REST API as shown in references/asset-export.md and references/component-generation.md.
  • Boundary markers: No explicit boundary markers or specific 'ignore instructions' delimiters are used when interpolating external design data into code templates.
  • Capability inventory: The skill uses fs.writeFile across several files to generate executable .tsx and .ts code.
  • Sanitization: While the skill performs naming normalization (e.g., normalizeFileName), it does not sanitize the contents of exported SVGs or component descriptions before embedding them in code strings.
  • [EXTERNAL_DOWNLOADS]: The skill downloads SVG files and design tokens from api.figma.com. Figma is a well-known and reputable service for design asset management, and these downloads are essential to the skill's primary purpose.
  • [COMMAND_EXECUTION]: The CI automation documentation in references/ci-automation.md describes the use of shell commands within GitHub Actions, such as npm install and npm run sync:design-tokens, to automate the synchronization process. These are standard developer practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:50 AM
Security Audit — agent-trust-hub — figma-developer