rename-layers-batch

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of natural language instructions and lacks executable scripts or configuration for external tool access. No evidence of obfuscation, hardcoded credentials, or malicious intent was found.\n- [PROMPT_INJECTION]: The skill processes external data from Figma files, including layer names and comments, which constitutes an indirect prompt injection surface. Malicious instructions placed in layer names could potentially influence the agent's behavior. However, the risk is mitigated as the skill is restricted to Figma design-file modifications and lacks access to sensitive system tools or network capabilities.\n
  • Ingestion points: Figma layer names, frames, components, instances, variables, styles, comments, sections, and annotations (SKILL.md).\n
  • Boundary markers: None identified.\n
  • Capability inventory: Scoped edits to Figma design files (renaming) described in Workflow.\n
  • Sanitization: None identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:32 AM
Security Audit — agent-trust-hub — rename-layers-batch