site-launch-checklist

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Figma files (such as layer names, text content, and comments) that could contain malicious instructions designed to influence the agent's behavior.\n
  • Ingestion points: Accesses Figma frames, components, instances, variables, styles, layers, prototype settings, comments, sections, and annotations (defined in SKILL.md).\n
  • Boundary markers: The skill does not implement specific delimiters or 'ignore' instructions to separate untrusted data from the agent's system instructions.\n
  • Capability inventory: The skill can perform scoped, reversible edits to the Figma file when the user requests fixes.\n
  • Sanitization: No explicit sanitization or validation logic is defined for the content extracted from the design file.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:32 AM
Security Audit — agent-trust-hub — site-launch-checklist