opencode-mcp-figma-auth

Warn

Audited by Socket on Jun 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose conflicts with Figma's documented access model by framing itself as a way to bypass agent whitelisting, while handling persistent auth tokens and installing an unverifiable local npm project. Data flows appear to go to the official Figma endpoint, so this is not confirmed credential theft, but the capability is not cleanly aligned with the stated ecosystem and carries meaningful trust risk.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 12:05 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdesign-skills%2Fopencode-mcp-figma-auth%2F@13c9faa9f9f65432f70a52f99e708169a68f295ce42f3d9a61abdfbc0c61c97c
Security Audit — socket — opencode-mcp-figma-auth