extract-figma-spec
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted content from Figma specifications and implementation source code, which creates a surface for indirect prompt injection.
- Ingestion points: The agent is instructed to observe and process values from Figma grounds and implementation source code or images (SKILL.md, steps 1 and 2).
- Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the ingested Figma data or source code.
- Capability inventory: The agent has the capability to write the results of its comparison to specified artifacts (SKILL.md, step 6).
- Sanitization: The workflow does not mention any validation, filtering, or sanitization of the content extracted from external sources.
Audit Metadata