figma-handoff-gate

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Figma text nodes, names, and descriptions (found in SKILL.md).
  • Ingestion points: The skill accesses n.characters from text nodes, as well as n.name and n.description from various Figma frames and component nodes.
  • Boundary markers: There are no explicit delimiters or boundary markers defined to separate the ingested Figma data from the agent's internal instructions.
  • Capability inventory: The skill utilizes figma_execute for Plugin API execution (providing write access to the design file) and figma_capture_screenshot for visual data extraction.
  • Sanitization: No sanitization or escaping is performed on the ingested content before it is included in the output report or used to determine automated fix logic.
  • [DYNAMIC_EXECUTION]: The skill generates JavaScript snippets from internal templates to be executed via the figma_execute tool (SKILL.md).
  • The generated code incorporates dynamic values such as node IDs and logic for scanning the Figma document, representing a low-risk use of dynamic script generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — figma-handoff-gate