figma-canon
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documentation correctly identifies Figma file contents (such as layer names, component descriptions, and annotations) as untrusted data. It provides specific instructions to ensure this data is escaped and sanitized before being used in shell commands or other sensitive operations to prevent injection attacks.
- [DYNAMIC_EXECUTION]: The skill guides agents in generating JavaScript scripts for the Figma Plugin API. While this involves dynamic code generation, the risk is mitigated by a comprehensive set of 'Hard Rules', templates, and safety checks designed to ensure operational stability and prevent unintended side effects.
- [EXTERNAL_DOWNLOADS]: The instructions reference the installation of official tools like
@figma/code-connect. These downloads are from a well-known service and are documented here as part of standard developer workflows. - [COMMAND_EXECUTION]: The reference materials contain examples of shell commands for benign tasks, such as font installation on macOS and querying the official Apple iTunes API for asset retrieval.
Audit Metadata