skills/simota/agent-skills/frame/Gen Agent Trust Hub

frame

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Figma (such as component descriptions and FigJam content) which could contain hidden instructions aimed at downstream agents. The skill provides clear 'extract, do not interpret' principles and structured handoff formats to mitigate accidental command execution by consumers.
  • Ingestion points: Data is imported through tools like get_design_context and get_figjam (referenced in SKILL.md).
  • Boundary markers: Structural handoff templates are defined in reference/handoff-formats.md, although they lack explicit 'ignore instructions' delimiters for extracted text fields.
  • Capability inventory: The skill manages Figma operations via MCP; however, the downstream agents it feeds (Artisan, Forge) often possess broader code implementation capabilities.
  • Sanitization: The skill focuses on structural mapping and does not detail specific sanitization protocols for raw text extracted from Figma nodes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — frame