mistica-figma
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill provides legitimate instructions for interacting with the Figma API to build UI components using the Mistica design system.
- [COMMAND_EXECUTION]: The skill contains JavaScript code snippets for use with Figma automation tools. These snippets are restricted to layout creation, grid configuration, and node property management (e.g.,
figma.createFrame,gridColumnSpan). No arbitrary or dangerous command execution was found. - [PROMPT_INJECTION]: No instructional overrides, role-play bypasses, or attempts to extract system prompts were detected. The instructions focus entirely on design system implementation.
- [DATA_EXFILTRATION]: No patterns indicative of data exfiltration or sensitive information harvesting were identified. The network-related tool calls (
get_libraries,search_design_system) are expected functionality for Figma-integrated skills. - [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or secrets are present in the documentation or code samples.
Audit Metadata