figma-to-code-component

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructions for translating Figma designs into code. Analysis of the skill's logic, workflow, and guardrails reveals no malicious intent, command execution, or network activity.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external Figma design data, which represents a potential ingestion point for indirect prompt injection.
  • Ingestion points: Figma design-file context (layers, comments, styles, variables) as defined in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands in the design data.
  • Capability inventory: The skill is limited to generating code snippets and handoff documentation; it lacks the ability to execute code, write to the filesystem, or access the network.
  • Sanitization: No specific sanitization or validation of the input text content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:32 AM
Security Audit — agent-trust-hub — figma-to-code-component