figma-swiftui
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches canonical workflow components from a well-known repository on GitHub belonging to Figma.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it processes untrusted data from Figma designs, but includes significant mitigations.
- Ingestion points: Figma design context retrieved via tools described in references/design-to-code.md.
- Boundary markers: SKILL.md explicitly labels the treatment of external content as trusted instructions as an anti-pattern.
- Capability inventory: The skill enables the agent to write and modify .swift files.
- Sanitization: The instructions mandate strict semantic mapping to idiomatic system components and tokens to prevent literal interpretation of potentially malicious design text.
Audit Metadata