states-completeness-check
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists of benign instructional content designed to improve UI design quality and does not exhibit any malicious patterns, obfuscation, or unauthorized access attempts.
- [NO_CODE]: No scripts, executables, or package manifests were found; the skill is entirely comprised of markdown-based instructions.
- [INDIRECT_PROMPT_INJECTION]: The skill has a theoretical attack surface for indirect prompt injection as it processes external Figma design data.
- Ingestion points: The agent reads Figma frames, components, instances, variables, styles, layers, prototype settings, comments, sections, and annotations (SKILL.md).
- Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the guidelines.
- Capability inventory: The agent is authorized to review design files and perform scoped, reversible edits to Figma elements.
- Sanitization: The instructions do not specify any validation or sanitization for text content within the ingested Figma elements.
Audit Metadata