figma-to-content

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose and most capabilities are coherent for a Figma-to-Adobe content publishing skill, and data primarily flows to official Adobe endpoints. The main concerns are transitive trust in multiple orchestrated skills, acceptance of arbitrary remote Figma MCP implementations, limited credential-file access, and the ability to perform code pushes and optional live publication; these are significant but not fundamentally incompatible with the stated purpose.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Aug 26, 2026, 03:49 PM
Package URL
pkg:socket/skills-sh/adobe%2Fskills%2Ffigma-to-content%2F@8c4ca0a3ef04e9d10ecca63dbc4deb232175316a28212521a57b0f7f4eae3bfb
Security Audit — socket — figma-to-content