webflow-mcp:figma-to-webflow
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests and processes untrusted data from external Figma designs to construct Webflow project structure and content.
- Ingestion points: External design data is fetched via Figma MCP tools such as
get_metadataandget_design_context(SKILL.md). - Boundary markers: The skill includes instructions to confirm design intent and placeholders with the user before building, which serves as a procedural mitigation, though it lacks technical markers to delimit untrusted data.
- Capability inventory: The skill has significant capabilities including site modification, asset creation, and publishing through the Webflow MCP Data API and Designer Bridge tools (SKILL.md).
- Sanitization: Validation logic is provided for security policy strings, and structural verification steps are recommended after data insertion.
- [COMMAND_EXECUTION]: The skill includes a shell command instruction to validate the integrity of S3 security policy strings using
printfandgrepbefore proceeding with asset uploads (references/assets-and-svg.md). - [EXTERNAL_DOWNLOADS]: The skill retrieves design assets, screenshots, and image bytes from Figma endpoints and downloads font files from Google Fonts to fulfill its design recreation purpose.
- [DATA_EXFILTRATION]: The skill performs authorized uploads of processed design assets to Webflow-managed S3 storage using presigned URLs provided by the platform (references/assets-and-svg.md).
Audit Metadata