figma-generate-library

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill is designed to ingest and analyze external codebase data (Phase 0: Discovery) to extract tokens and components. This creates a potential surface where malicious instructions embedded in codebase comments or files could influence the agent's behavior during the generation process. However, this is the core intended functionality of the skill, and it includes robust mitigations such as mandatory user checkpoints at every phase and manual verification of generated content through screenshots and metadata inspections.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:14 AM