component-audit
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted data from Figma design files (layer names, properties, and comments) and has the capability to perform write operations, which creates a surface for indirect prompt injection.
- Ingestion points: Figma design-file context including frames, components, instances, layers, and comment threads in SKILL.md.
- Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions embedded within the design metadata.
- Capability inventory: The agent can read design file structure and metadata, and is instructed to "fix straightforward issues" such as renaming layers and aligning padding.
- Sanitization: No sanitization or validation logic is defined for the design-file content before processing or using it in decision-making.
Audit Metadata