sunnyside-figma-context-mcp
Warn
Audited by Socket on May 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The functional scope mostly matches the stated Figma design-to-code purpose, and the documented credential/data flows are largely proportionate and local/Figma-directed. The main concern is install trust: the recommended source is an unverifiable personal GitHub repo with inconsistent publisher identity and weak release provenance, so the skill carries elevated supply-chain risk even without clear evidence of malicious exfiltration.
Confidence: 88%Severity: 74%
Audit Metadata