figma-workflow-auditor
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to evaluate external content like transcripts, reports, and other skills, creating a potential surface for indirect prompt injection.\n
- Ingestion points: The workflow involves reviewing "prompt, plan, skill, transcript, report, or file change" (SKILL.md).\n
- Boundary markers: Absent. The instructions do not specify delimiters or guidelines to separate the untrusted content being audited from the skill's own logic.\n
- Capability inventory: The skill does not request access to high-risk tools, network operations, or file system writing capabilities.\n
- Sanitization: Absent. There are no instructions for filtering or escaping external content before processing.
Audit Metadata