figma-comment-fix-loop
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon Figma comments, which are external, untrusted strings. Maliciously crafted comments could attempt to influence the agent's behavior or trigger unintended actions during the 'analysis' and 'fix' phases.
- Ingestion points: Comments are retrieved via the
figma_get_commentstool, direct REST API calls (GET https://api.figma.com/v1/files/<fileKey>/comments), or direct user paste. - Boundary markers: The skill lacks explicit instructions for the agent to treat comment text as data rather than instructions, and there are no delimiters or sanitization steps mentioned.
- Capability inventory: The agent has broad capabilities including executing JavaScript in the Figma environment via
figma_execute, performing network operations viacurl, and executing system-level scripts viaosascript. - Sanitization: No sanitization or validation of the comment content is performed before the agent 'interprets' and 'applies' the feedback.
- [COMMAND_EXECUTION]: The skill uses sensitive macOS-specific commands to automate the user interface and capture visual evidence.
- Evidence: Usage of
osascriptto activate the Figma application and manipulate windows (AXRaise). This requires Accessibility permissions on the host system. - Evidence: Usage of
screencaptureto record regions of the user's desktop. - [DYNAMIC_EXECUTION]: The skill relies heavily on the dynamic execution of code within the Figma plugin sandbox to perform modifications and exports.
- Evidence: Instructions for complex JavaScript logic to be run via
figma_execute, including font loading, node resizing, and property updates. - Evidence: Instructions for the agent to write and run a temporary local HTTP server to handle image exports, which involves dynamic script generation and local network binding.
- [CREDENTIALS_SAFE]: The skill references the use of
FIGMA_ACCESS_TOKENbut provides secure guidance by instructing the agent not to print, write, or request the token value in chat, favoring environment variables.
Audit Metadata