legacy-styles-to-variables
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests potentially untrusted data from the Figma environment, specifically 'comments' and 'annotations', to inform its migration logic. An attacker could embed malicious instructions in these fields to influence the agent's cleanup actions.\n- Ingestion points: Figma comments, sections, annotations, and layer names.\n- Boundary markers: The skill includes instructions to 'ask at most two targeted questions' and 'ask before file-wide edits', which provide limited boundaries against automated obedience to injected instructions.\n- Capability inventory: The skill is authorized to modify Figma layer properties, including fills, strokes, and variable bindings.\n- Sanitization: There is no explicit instruction to sanitize or ignore instructions embedded within the Figma comments or metadata.
Audit Metadata