figma-comment-fix-loop

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon Figma comments, which are external, untrusted strings. Maliciously crafted comments could attempt to influence the agent's behavior or trigger unintended actions during the 'analysis' and 'fix' phases.
  • Ingestion points: Comments are retrieved via the figma_get_comments tool, direct REST API calls (GET https://api.figma.com/v1/files/<fileKey>/comments), or direct user paste.
  • Boundary markers: The skill lacks explicit instructions for the agent to treat comment text as data rather than instructions, and there are no delimiters or sanitization steps mentioned.
  • Capability inventory: The agent has broad capabilities including executing JavaScript in the Figma environment via figma_execute, performing network operations via curl, and executing system-level scripts via osascript.
  • Sanitization: No sanitization or validation of the comment content is performed before the agent 'interprets' and 'applies' the feedback.
  • [COMMAND_EXECUTION]: The skill uses sensitive macOS-specific commands to automate the user interface and capture visual evidence.
  • Evidence: Usage of osascript to activate the Figma application and manipulate windows (AXRaise). This requires Accessibility permissions on the host system.
  • Evidence: Usage of screencapture to record regions of the user's desktop.
  • [DYNAMIC_EXECUTION]: The skill relies heavily on the dynamic execution of code within the Figma plugin sandbox to perform modifications and exports.
  • Evidence: Instructions for complex JavaScript logic to be run via figma_execute, including font loading, node resizing, and property updates.
  • Evidence: Instructions for the agent to write and run a temporary local HTTP server to handle image exports, which involves dynamic script generation and local network binding.
  • [CREDENTIALS_SAFE]: The skill references the use of FIGMA_ACCESS_TOKEN but provides secure guidance by instructing the agent not to print, write, or request the token value in chat, favoring environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — figma-comment-fix-loop