figma-generate-design

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its ingestion of local code. 1. Ingestion points: The skill reads TypeScript, Kotlin, and Swift source files to extract component keys and URLs (SKILL.md, Step 2a-i). 2. Boundary markers: No explicit delimiters or instructions are used to signal the agent to ignore potentially malicious content within the source files. 3. Capability inventory: The skill possesses significant capabilities, including the execution of arbitrary JavaScript within Figma via the use_figma tool and the generation of visual captures. 4. Sanitization: The workflow does not include explicit validation or sanitization of the data extracted from the codebase before it is used in script generation.
  • [DYNAMIC_EXECUTION]: The core functionality of the skill involves generating and executing JavaScript at runtime through the use_figma MCP tool (SKILL.md, Steps 3-4). While these scripts follow documented templates, the interpolation of local environment data into executable scripts represents a dynamic execution pattern.
  • [EXTERNAL_DOWNLOADS]: The skill's documentation and changelog reference official example workflows and integration guides from Figma's GitHub repository. These references are used to maintain alignment with official design system standards and are documented neutrally.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:18 AM
Security Audit — agent-trust-hub — figma-generate-design