figma-designer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external Figma designs (metadata, component names, text layers) via an MCP server. Maliciously crafted Figma designs could potentially contain instructions aimed at overriding the agent's behavior or manipulating the generated PRDs.
  • Ingestion points: Figma file metadata, node details, and component information (SKILL.md).
  • Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are present in the analysis workflow.
  • Capability inventory: The skill is allowed to use powerful tools including Bash, Write, Edit, and WebFetch (SKILL.md).
  • Sanitization: The instructions do not define sanitization or validation steps for text content extracted from Figma frames.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:21 AM
Security Audit — agent-trust-hub — figma-designer