talktofigma-desktop-mcp
Warn
Audited by Socket on May 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities largely match its stated Figma-bridge purpose, and the documented data flow is local and coherent. The main concern is install trust: the skill published by ara.so instructs users to download and trust a separate desktop binary from Grab GitHub Releases and to bypass OS warnings, which raises supply-chain risk even though the repo/releases appear legitimate and purpose-aligned.
Confidence: 85%Severity: 58%
Audit Metadata