figma-orient
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted text data (UI copy) from Figma canvas layers, creating a surface for potential instruction injection.
- Ingestion points: Extracted text content from Figma pages and sections via the
figma_executetool. - Boundary markers: Instructions lack specific delimiters to isolate external text content from the agent's instructional context during the mapping process.
- Capability inventory: The skill can write the resulting data to
docs/figma-map.mdor the agent's memory system. - Sanitization: No specific security sanitization or filtering is performed on the ingested text strings.
- [DYNAMIC_EXECUTION]: The skill utilizes runtime-generated JavaScript snippets to interface with the Figma API via the
figma_executetool. - Evidence: Usage of
getNodeByIdAsyncandfindAllmethods within scripts passed to thefigma_executetool. - Context: Execution is limited to the Figma plugin runtime environment and uses predefined templates for structural analysis.
Audit Metadata