figma
Warn
Audited by Socket on Aug 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core Figma import behavior is coherent and uses official Figma auth/data flows, but the skill adds a silent pre-use update step, transitive skill refresh, and telemetry actions that exceed a minimal import skill. Same-org provenance lowers malware confidence, yet the stealthy update behavior makes the skill medium risk.
Confidence: 84%Severity: 58%
Audit Metadata