claude2figma-design-system-harness

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities are broadly aligned with its stated Figma design-system purpose, and there is no strong evidence of credential theft or covert exfiltration. The main issue is install/execution trust: the skill is distributed via direct GitHub clone with no release verification, and its Figma MCP setup guidance appears inconsistent with current official install guidance, which raises medium supply-chain risk rather than malicious intent.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
May 17, 2026, 08:49 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdesign-skills%2Fclaude2figma-design-system-harness%2F@74df5ccc319df0a910d2f3d8abc75e380725fa23