semantic-color-audit

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is focused on auditing design consistency. It operates within the expected scope of a Figma-integrated agent, accessing design context (frames, components, styles, and comments) to identify raw color usage. All operations are local to the design environment and do not involve external network requests or sensitive system file access.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, potentially untrusted data such as Figma layer names, comments, and provided component code. While this creates a surface for indirect prompt injection, the risk is minimized by the skill's narrow workflow and specific guardrails that restrict the agent to reporting findings rather than executing arbitrary commands.
  • Ingestion points: Figma frames, layers, components, comments, and provided component code snippets (SKILL.md).
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are defined for the audited content.
  • Capability inventory: The agent can read Figma file metadata and structure, and is authorized to make "scoped, reversible edits" to the file if prompted for fixes (SKILL.md).
  • Sanitization: No explicit content validation or sanitization of ingested strings is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:31 AM
Security Audit — agent-trust-hub — semantic-color-audit