figma-bridge-html-export

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose and capabilities mostly align, and data stays local in the documented flow. The main concern is install trust: the skill is published by ara.so but directs users to clone and run a personal GitHub repo, creating moderate supply-chain risk without clear same-org provenance. No strong signs of malware, credential theft, or covert exfiltration are present.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
May 18, 2026, 07:54 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdesign-skills%2Ffigma-bridge-html-export%2F@ba46c0b85dd11622479e3856ab87e41adc4d2e68