figma-automation
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to add an external MCP server endpoint (
https://rube.app/mcp). This is a standard configuration step for using the Rube platform and is necessary for the skill's stated functionality. - [PROMPT_INJECTION]: The skill ingests untrusted content from external sources, specifically Figma design files and comments via tools like
FIGMA_GET_FILE_JSONandFIGMA_GET_COMMENTS_IN_A_FILE. This creates a surface for indirect prompt injection where malicious instructions embedded in Figma comments or node names could attempt to influence agent behavior. No explicit boundary markers or sanitization steps are defined in the instructions.
Audit Metadata