content-tone-review

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill accesses content from Figma design files, including layer text, comments, and variables. This data access is necessary for the core functionality of reviewing design copy and is standard for the design-file reviewer role.
  • [COMMAND_EXECUTION]: The skill includes instructions to perform 'scoped, reversible edits' on the design file when explicitly asked to apply fixes. This write capability is limited in scope and intended to facilitate direct UI text updates based on the review results.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes untrusted text from design files and external guidelines.
  • Ingestion points: Figma text layers, frames, components, comments, and external voice/tone guidelines provided via connector (SKILL.md).
  • Boundary markers: Not identified; the instructions do not explicitly define delimiters to separate design content from the agent's instructions.
  • Capability inventory: The skill has file-write capabilities through scoped edits to Figma files (SKILL.md).
  • Sanitization: Not identified; the skill is designed to process strings as raw data for linguistic analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:31 AM
Security Audit — agent-trust-hub — content-tone-review