Back to skill

Security audit

Figma设计集成-专业版

Security checks across malware telemetry and agentic risk

Overview

This Figma skill is mostly purpose-aligned, but it includes broad activation wording and team comment deletion without clear user confirmation guidance.

Review before installing if you use Figma in a team setting. Only use it for explicit Figma tasks, keep the MorphixAI key scoped and revocable, and require clear approval before posting or deleting comments in shared files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description is extremely broad, covering generic design creation, UI work, posters, branding, enterprise workflows, and automation, which increases the chance of unintended invocation on loosely related prompts. In an agent context with read/exec/write tools enabled, overbroad routing can cause the skill to handle requests outside a narrowly intended scope, increasing the risk of unnecessary file access, command execution, or external API use.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill includes a destructive action to delete comments as part of a workflow but does not require confirmation, present impact warnings, or describe recovery limitations. In a collaborative design environment, accidental or automated deletion can remove audit trail and reviewer context, causing integrity and accountability issues across teams.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.