figma-handoff-gate
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Figma text nodes, names, and descriptions (found in SKILL.md).
- Ingestion points: The skill accesses
n.charactersfrom text nodes, as well asn.nameandn.descriptionfrom various Figma frames and component nodes. - Boundary markers: There are no explicit delimiters or boundary markers defined to separate the ingested Figma data from the agent's internal instructions.
- Capability inventory: The skill utilizes
figma_executefor Plugin API execution (providing write access to the design file) andfigma_capture_screenshotfor visual data extraction. - Sanitization: No sanitization or escaping is performed on the ingested content before it is included in the output report or used to determine automated fix logic.
- [DYNAMIC_EXECUTION]: The skill generates JavaScript snippets from internal templates to be executed via the
figma_executetool (SKILL.md). - The generated code incorporates dynamic values such as node IDs and logic for scanning the Figma document, representing a low-risk use of dynamic script generation.
Audit Metadata