figma-ui-mcp-bridge
Warn
Audited by Socket on May 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s capabilities largely match its stated Figma-bridge purpose and its localhost data flow is coherent, but install trust is inconsistent with the publisher identity. The main concerns are transitive MCP installation and a Figma plugin delivered as an unpinned raw GitHub zip from a personal account, which creates meaningful supply-chain risk even without evidence of overt exfiltration.
Confidence: 88%Severity: 72%
Audit Metadata