huolala-figma-mcp
Warn
Audited by Snyk on Jun 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The required runtime workflow calls the MCP tool
figma_to_code_packagewith a user-suppliedfigma_url, and the service fetches that Figma design content (public web content / third-party authored text) and then ingests it into the generated ZIP as readableindex.htmlanddsl.jsonthat the agent uses as LLM context—so outsider free text can flow into the LLM via the fetched design.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata