figma-developer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted design metadata and assets (component names, descriptions, styles, and SVG content) from the Figma API and incorporates them into generated React components, CSS, and TypeScript files. A compromised or malicious Figma file could theoretically influence the generated code or styles.
- Ingestion points: Data is fetched via
api.getFile,api.getImages, andfetchfrom the Figma REST API as shown inreferences/asset-export.mdandreferences/component-generation.md. - Boundary markers: No explicit boundary markers or specific 'ignore instructions' delimiters are used when interpolating external design data into code templates.
- Capability inventory: The skill uses
fs.writeFileacross several files to generate executable.tsxand.tscode. - Sanitization: While the skill performs naming normalization (e.g.,
normalizeFileName), it does not sanitize the contents of exported SVGs or component descriptions before embedding them in code strings. - [EXTERNAL_DOWNLOADS]: The skill downloads SVG files and design tokens from
api.figma.com. Figma is a well-known and reputable service for design asset management, and these downloads are essential to the skill's primary purpose. - [COMMAND_EXECUTION]: The CI automation documentation in
references/ci-automation.mddescribes the use of shell commands within GitHub Actions, such asnpm installandnpm run sync:design-tokens, to automate the synchronization process. These are standard developer practices.
Audit Metadata