figma-bridge-doctor

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMPERSISTENCEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PERSISTENCE]: The skill includes an optional macOS LaunchAgent template (scripts/com.figma-maxxing.bridge-watchdog.plist.template) and a watchdog script (scripts/figma-watchdog.sh). If installed by the user, these components maintain a background process that persists across logins to monitor a signal file and automate UI interactions in Figma.
  • [DYNAMIC_EXECUTION]: The scripts/mcp-direct/daemon.mjs script dynamically calculates a file path at runtime by scanning the npx cache directory for the figma-console-mcp package. It ranks available versions using semver and executes the discovered local.js file using child_process.spawn.
  • [COMMAND_EXECUTION]: Multiple scripts, including scripts/figma-bridge-reset.sh, scripts/figma-status.sh, and the instructions in references/deep-recovery.md, utilize shell commands such as kill -9, pgrep, and lsof to identify and terminate processes belonging to other agent sessions or orphaned servers.
  • [PRIVILEGE_ESCALATION]: The automation relies on AppleScript (osascript) to interact with the Figma Desktop UI. This functionality requires the user to grant "Accessibility" permissions to the parent application hosting the agent, allowing the skill to control system events and menu items.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from live Figma files that may be modified by other agents or users. SKILL.md explicitly defines a "rival-write audit" to detect and manage these external modifications, identifying a vulnerability surface where the state of shared files can influence agent decision-making. Evidence: Ingestion points include tool outputs from the figma-console-mcp bridge; capabilities include JS execution via figma_execute and process management; boundary markers and specific sanitization for runtime data are not explicitly enforced.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — figma-bridge-doctor