figma-orient

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted text data (UI copy) from Figma canvas layers, creating a surface for potential instruction injection.
  • Ingestion points: Extracted text content from Figma pages and sections via the figma_execute tool.
  • Boundary markers: Instructions lack specific delimiters to isolate external text content from the agent's instructional context during the mapping process.
  • Capability inventory: The skill can write the resulting data to docs/figma-map.md or the agent's memory system.
  • Sanitization: No specific security sanitization or filtering is performed on the ingested text strings.
  • [DYNAMIC_EXECUTION]: The skill utilizes runtime-generated JavaScript snippets to interface with the Figma API via the figma_execute tool.
  • Evidence: Usage of getNodeByIdAsync and findAll methods within scripts passed to the figma_execute tool.
  • Context: Execution is limited to the Figma plugin runtime environment and uses predefined templates for structural analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — figma-orient