dev-handoff-prep

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates strictly within the Figma design ecosystem, focusing on design-system alignment and developer handoff documentation. No patterns related to credential harvesting, unauthorized network communication, or persistence were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the active Figma design file, which constitutes an attack surface for indirect prompt injection.
  • Ingestion points: The skill reads frame names, layer names, component properties, variables, and user comments within the SKILL.md 'Supported Context'.
  • Boundary markers: The instructions do not define specific delimiters to distinguish between design metadata and agent instructions.
  • Capability inventory: The agent can perform scoped, reversible edits to layer names, styles, and add annotations to the design file.
  • Sanitization: No explicit sanitization or filtering of design layer content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:31 AM
Security Audit — agent-trust-hub — dev-handoff-prep