design-to-code-fidelity

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads design references and image assets from Figma's official REST API (api.figma.com). As a well-known service, these references are documented neutrally and do not escalate the verdict.
  • [COMMAND_EXECUTION]: The skill executes local shell scripts to manage image comparisons via ImageMagick and browser automation via Playwright. These are standard operations for UI testing.
  • [DYNAMIC_EXECUTION]: Browser automation in render-capture.mjs supports injecting initialization scripts into the page context, which is used for pinning time and state. figma-export.sh also utilizes an embedded Python script for processing API responses.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from web pages and design files, which represents a potential injection surface. However, the risk is addressed through a structured evidence tier system (T1-T4) that enforces manual review of the generated comparison artifacts and manifests.
  • [SAFE]: No credentials exposure, persistence mechanisms, or obfuscation techniques were detected in the skill code or instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:59 PM
Security Audit — agent-trust-hub — design-to-code-fidelity