states-completeness-check

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists of benign instructional content designed to improve UI design quality and does not exhibit any malicious patterns, obfuscation, or unauthorized access attempts.
  • [NO_CODE]: No scripts, executables, or package manifests were found; the skill is entirely comprised of markdown-based instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a theoretical attack surface for indirect prompt injection as it processes external Figma design data.
  • Ingestion points: The agent reads Figma frames, components, instances, variables, styles, layers, prototype settings, comments, sections, and annotations (SKILL.md).
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the guidelines.
  • Capability inventory: The agent is authorized to review design files and perform scoped, reversible edits to Figma elements.
  • Sanitization: The instructions do not specify any validation or sanitization for text content within the ingested Figma elements.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:32 AM
Security Audit — agent-trust-hub — states-completeness-check