figma-mcp-integration

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s Figma-read/write scope matches its stated purpose, but its trust model is weak. It relies on download-and-execute patterns and executes a third-party MCP server from an unrelated publisher via mutable install paths, creating meaningful supply-chain and design-data exposure risk without clear same-org provenance.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
May 18, 2026, 07:54 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdesign-skills%2Ffigma-mcp-integration%2F@9c8597d0e17b4461409ac2d3ac5f0e12719990ad