Security audit
Figma Annotation Guide
Security checks for vulnerabilities and agentic risk
Overview
This skill is a plain writing guide for producing Figma developer handoff annotations and does not request code execution, credentials, persistence, or sensitive access.
Installers should understand that this skill helps draft Figma handoff notes from information they provide. Avoid pasting confidential product details unless you are comfortable sharing them with the agent session, but the skill itself does not request credentials or special access.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
