design-to-code-fidelity
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads design references and image assets from Figma's official REST API (api.figma.com). As a well-known service, these references are documented neutrally and do not escalate the verdict.
- [COMMAND_EXECUTION]: The skill executes local shell scripts to manage image comparisons via ImageMagick and browser automation via Playwright. These are standard operations for UI testing.
- [DYNAMIC_EXECUTION]: Browser automation in
render-capture.mjssupports injecting initialization scripts into the page context, which is used for pinning time and state.figma-export.shalso utilizes an embedded Python script for processing API responses. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from web pages and design files, which represents a potential injection surface. However, the risk is addressed through a structured evidence tier system (T1-T4) that enforces manual review of the generated comparison artifacts and manifests.
- [SAFE]: No credentials exposure, persistence mechanisms, or obfuscation techniques were detected in the skill code or instructions.
Audit Metadata