figma-slop-check
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill requires the agent to generate and execute JavaScript code through the
figma_executetool. This enables the agent to interact with the Figma document's internal data model and properties at runtime.\n- [INDIRECT_PROMPT_INJECTION]:\n - Ingestion points: The skill reads and processes user-controlled text content from Figma layers (
charactersproperty), layer names, and component properties.\n - Boundary markers: There are no defined delimiters or instructions to treat the data retrieved from Figma as untrusted or to ignore instructions embedded within text nodes.\n
- Capability inventory: The skill has the ability to execute scripts via
figma_execute, capture screenshots, and perform file system writes to the local project directory.\n - Sanitization: The instructions do not specify any validation or sanitization of the strings retrieved from the Figma documents.\n- [COMMAND_EXECUTION]: The skill performs local file system operations to read and write audit history, accepted drift, and exception ledgers in a
.figma-slop-check/directory to maintain state across sessions.
Audit Metadata