figma-preflight
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Python script
scripts/figma_lock.pyto manage advisory file locks. This script uses standard libraries for file-based locking and JSON storage in~/.cache/figma-maxxing/locks/. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting untrusted data from Figma files during its validation checks.
- Ingestion points: Reads Figma metadata via
get_metadata, variable definitions viaget_variable_defs, and design system components viasearch_design_system(referenced in SKILL.md). - Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the retrieved Figma content.
- Capability inventory: The agent has Figma write capabilities (
figma_execute,use_figma) which are gated by this skill. - Sanitization: There is no explicit mention of sanitizing or escaping the data retrieved from the Figma API before processing it.
Audit Metadata