webflow-mcp:figma-to-webflow

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests and processes untrusted data from external Figma designs to construct Webflow project structure and content.
  • Ingestion points: External design data is fetched via Figma MCP tools such as get_metadata and get_design_context (SKILL.md).
  • Boundary markers: The skill includes instructions to confirm design intent and placeholders with the user before building, which serves as a procedural mitigation, though it lacks technical markers to delimit untrusted data.
  • Capability inventory: The skill has significant capabilities including site modification, asset creation, and publishing through the Webflow MCP Data API and Designer Bridge tools (SKILL.md).
  • Sanitization: Validation logic is provided for security policy strings, and structural verification steps are recommended after data insertion.
  • [COMMAND_EXECUTION]: The skill includes a shell command instruction to validate the integrity of S3 security policy strings using printf and grep before proceeding with asset uploads (references/assets-and-svg.md).
  • [EXTERNAL_DOWNLOADS]: The skill retrieves design assets, screenshots, and image bytes from Figma endpoints and downloads font files from Google Fonts to fulfill its design recreation purpose.
  • [DATA_EXFILTRATION]: The skill performs authorized uploads of processed design assets to Webflow-managed S3 storage using presigned URLs provided by the platform (references/assets-and-svg.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 06:07 AM
Security Audit — agent-trust-hub — webflow-mcp:figma-to-webflow