component-audit

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted data from Figma design files (layer names, properties, and comments) and has the capability to perform write operations, which creates a surface for indirect prompt injection.
  • Ingestion points: Figma design-file context including frames, components, instances, layers, and comment threads in SKILL.md.
  • Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions embedded within the design metadata.
  • Capability inventory: The agent can read design file structure and metadata, and is instructed to "fix straightforward issues" such as renaming layers and aligning padding.
  • Sanitization: No sanitization or validation logic is defined for the design-file content before processing or using it in decision-making.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:31 AM
Security Audit — agent-trust-hub — component-audit