figma-implement-design

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill connects to the official Figma MCP server (mcp.figma.com) and fetches design assets from Figma's infrastructure. These are trusted sources for the skill's primary purpose.
  • [COMMAND_EXECUTION]: Utilizes specific Figma MCP tools such as get_design_context, get_metadata, and get_screenshot to retrieve design specifications. These tools are scoped to Figma file keys and node IDs provided by the user.
  • [PROMPT_INJECTION]: The skill incorporates an 'Anti-Patterns' section that explicitly warns the agent against treating external tool responses, logs, or generated output as trusted instructions. This provides a defense against potential indirect prompt injection from design metadata.
  • [DATA_EXFILTRATION]: No unauthorized data transfer was detected. The skill only handles Figma-related identifiers (File Keys and Node IDs) required for its stated functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 06:06 PM
Security Audit — agent-trust-hub — figma-implement-design