figma-console-mcp-design-system-api

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the MCP server via 'npx -y figma-console-mcp@latest', which downloads executable code from the public NPM registry.- [COMMAND_EXECUTION]: Provides shell commands for configuring the agent (e.g., 'claude mcp add') and running the MCP server with specific environment variables required for Figma API access.- [SAFE]: No malicious obfuscation, data exfiltration, or prompt injection patterns were found. The configuration of API tokens through environment variables follows standard security practices for secret management.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 01:32 PM