opencode-mcp-figma-auth
Warn
Audited by Socket on Jun 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose conflicts with Figma's documented access model by framing itself as a way to bypass agent whitelisting, while handling persistent auth tokens and installing an unverifiable local npm project. Data flows appear to go to the official Figma endpoint, so this is not confirmed credential theft, but the capability is not cleanly aligned with the stated ecosystem and carries meaningful trust risk.
Confidence: 100%Severity: 60%
Audit Metadata