figma-to-ai-prompter

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capability is coherent with the stated Figma-to-prompt purpose and official Figma API use is appropriate, but install trust is weakened by a publisher/source mismatch: the skill is branded as ara.so while the code source is a personal GitHub repo with limited release provenance and an inconsistent npm install step. No direct credential harvesting or third-party credential proxying is shown, so this is not confirmed malicious, but it carries medium supply-chain risk.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 18, 2026, 12:14 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdesign-skills%2Ffigma-to-ai-prompter%2F@d7124cf9e166d1c32412d7ffa8ed7b98b6a5b9bb