frame
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Figma (such as component descriptions and FigJam content) which could contain hidden instructions aimed at downstream agents. The skill provides clear 'extract, do not interpret' principles and structured handoff formats to mitigate accidental command execution by consumers.
- Ingestion points: Data is imported through tools like
get_design_contextandget_figjam(referenced inSKILL.md). - Boundary markers: Structural handoff templates are defined in
reference/handoff-formats.md, although they lack explicit 'ignore instructions' delimiters for extracted text fields. - Capability inventory: The skill manages Figma operations via MCP; however, the downstream agents it feeds (Artisan, Forge) often possess broader code implementation capabilities.
- Sanitization: The skill focuses on structural mapping and does not detail specific sanitization protocols for raw text extracted from Figma nodes.
Audit Metadata