follow-ds-guidelines
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from Figma design files, such as layer names and text content, which introduces a potential attack surface for instructions embedded in the data.
- Ingestion points: The skill ingests data from frames, components, instances, variables, styles, layers, comments, and annotations within Figma (SKILL.md, Supported Context).
- Boundary markers: None identified; the instructions do not specify the use of delimiters or clear separation between system instructions and design-file content.
- Capability inventory: The skill can inspect file metadata, identify enabled libraries, report violations, and swap design tokens (styles and variables) (SKILL.md, Workflow).
- Sanitization: There is no explicit sanitization or validation of the text data extracted from the Figma layers or comments before the agent processes them.
Audit Metadata