talktofigma-desktop-mcp

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities largely match its stated Figma-bridge purpose, and the documented data flow is local and coherent. The main concern is install trust: the skill published by ara.so instructs users to download and trust a separate desktop binary from Grab GitHub Releases and to bypass OS warnings, which raises supply-chain risk even though the repo/releases appear legitimate and purpose-aligned.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
May 18, 2026, 04:59 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdesign-skills%2Ftalktofigma-desktop-mcp%2F@68462fa6371e3645c10629e5b33f95025945212a