figma-preflight

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python script scripts/figma_lock.py to manage advisory file locks. This script uses standard libraries for file-based locking and JSON storage in ~/.cache/figma-maxxing/locks/.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting untrusted data from Figma files during its validation checks.
  • Ingestion points: Reads Figma metadata via get_metadata, variable definitions via get_variable_defs, and design system components via search_design_system (referenced in SKILL.md).
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the retrieved Figma content.
  • Capability inventory: The agent has Figma write capabilities (figma_execute, use_figma) which are gated by this skill.
  • Sanitization: There is no explicit mention of sanitizing or escaping the data retrieved from the Figma API before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — figma-preflight