figma-bridge-doctor
Warn
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: MEDIUMPERSISTENCEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PERSISTENCE]: The skill includes an optional macOS LaunchAgent template (
scripts/com.figma-maxxing.bridge-watchdog.plist.template) and a watchdog script (scripts/figma-watchdog.sh). If installed by the user, these components maintain a background process that persists across logins to monitor a signal file and automate UI interactions in Figma. - [DYNAMIC_EXECUTION]: The
scripts/mcp-direct/daemon.mjsscript dynamically calculates a file path at runtime by scanning thenpxcache directory for thefigma-console-mcppackage. It ranks available versions using semver and executes the discoveredlocal.jsfile usingchild_process.spawn. - [COMMAND_EXECUTION]: Multiple scripts, including
scripts/figma-bridge-reset.sh,scripts/figma-status.sh, and the instructions inreferences/deep-recovery.md, utilize shell commands such askill -9,pgrep, andlsofto identify and terminate processes belonging to other agent sessions or orphaned servers. - [PRIVILEGE_ESCALATION]: The automation relies on AppleScript (
osascript) to interact with the Figma Desktop UI. This functionality requires the user to grant "Accessibility" permissions to the parent application hosting the agent, allowing the skill to control system events and menu items. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from live Figma files that may be modified by other agents or users.
SKILL.mdexplicitly defines a "rival-write audit" to detect and manage these external modifications, identifying a vulnerability surface where the state of shared files can influence agent decision-making. Evidence: Ingestion points include tool outputs from the figma-console-mcp bridge; capabilities include JS execution viafigma_executeand process management; boundary markers and specific sanitization for runtime data are not explicitly enforced.
Audit Metadata