figma-mcp-server

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides integration with official Figma services and does not contain malicious code or patterns.
  • [EXTERNAL_DOWNLOADS]: The skill fetches design data and assets from official Figma endpoints (mcp.figma.com) and references the official Figma mcp-server-guide repository on GitHub.
  • [COMMAND_EXECUTION]: Installation instructions point to official plugins and extensions for Claude, Cursor, and Gemini CLI, which are standard procedures for MCP client configuration.
  • [CREDENTIALS_UNSAFE]: The documentation correctly identifies that MCP handles authentication automatically and provides safe guidance for the use of environment variables for manual API token management.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 04:50 PM
Security Audit — agent-trust-hub — figma-mcp-server