extract-figma-spec

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted content from Figma specifications and implementation source code, which creates a surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to observe and process values from Figma grounds and implementation source code or images (SKILL.md, steps 1 and 2).
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the ingested Figma data or source code.
  • Capability inventory: The agent has the capability to write the results of its comparison to specified artifacts (SKILL.md, step 6).
  • Sanitization: The workflow does not mention any validation, filtering, or sanitization of the content extracted from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 01:16 AM
Security Audit — agent-trust-hub — extract-figma-spec