dev-handoff-prep
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates strictly within the Figma design ecosystem, focusing on design-system alignment and developer handoff documentation. No patterns related to credential harvesting, unauthorized network communication, or persistence were found.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the active Figma design file, which constitutes an attack surface for indirect prompt injection.
- Ingestion points: The skill reads frame names, layer names, component properties, variables, and user comments within the SKILL.md 'Supported Context'.
- Boundary markers: The instructions do not define specific delimiters to distinguish between design metadata and agent instructions.
- Capability inventory: The agent can perform scoped, reversible edits to layer names, styles, and add annotations to the design file.
- Sanitization: No explicit sanitization or filtering of design layer content is mentioned.
Audit Metadata