content-inventory
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill instructions do not contain any requests for network access, file system modifications, or privileged execution. It is a standard reporting tool.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted text layers from Figma design files, which could potentially contain malicious instructions intended to influence the agent's behavior. * Ingestion points: Figma text layers, frames, components, and annotations in SKILL.md. * Boundary markers: The skill includes explicit instructions to 'Preserve exact current text verbatim' and 'Capture visible copy exactly first', which helps prevent the agent from following embedded instructions. * Capability inventory: The skill has no identified capabilities for network operations, command execution, or file writing beyond Figma context edits in SKILL.md. * Sanitization: No sanitization methods are specified, as the output is intended for human review.
Audit Metadata