skills/pixel-point/toolcraft/figma/Gen Agent Trust Hub

figma

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of purely instructional markdown content. No executable scripts, network exfiltration, or hardcoded credentials were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a workflow for ingesting and processing data from external Figma files, which serves as a potential surface for indirect prompt injection. This is evaluated as safe as it is fundamental to the skill's purpose and lacks autonomous dangerous capabilities.
  • Ingestion points: Figma file content (nodes, layers, components, variables) referenced in SKILL.md.
  • Boundary markers: None specified; the agent is instructed to read raw node data.
  • Capability inventory: Interaction with Toolcraft schema controls and product renderer output as described in SKILL.md.
  • Sanitization: No explicit sanitization of Figma metadata or node content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 06:15 AM
Security Audit — agent-trust-hub — figma