vibefigma-figma-to-react

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose broadly matches its capabilities, but it relies on executing an external npm tool from a publisher not clearly tied to the skill author and forwards sensitive Figma credentials directly to that tool. Data flows are mostly proportionate to Figma-to-code conversion, yet install-trust and credential-forwarding risks make the overall skill medium-to-high risk rather than benign.

Confidence: 79%Severity: 68%
Audit Metadata
Analyzed At
May 17, 2026, 03:26 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdesign-skills%2Fvibefigma-figma-to-react%2F@881b7b3c8a4f39916ee81761370ef2c3fa232324