figma

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Figma import behavior is coherent and uses official Figma auth/data flows, but the skill adds a silent pre-use update step, transitive skill refresh, and telemetry actions that exceed a minimal import skill. Same-org provenance lowers malware confidence, yet the stealthy update behavior makes the skill medium risk.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Aug 21, 2026, 11:57 PM
Package URL
pkg:socket/skills-sh/heygen-com%2Fhyperframes%2Ffigma%2F@d646cb12d469c721005f58fc84e05d5f09d4274ef7bde9e3ccbe53616d169b3a
Security Audit — socket — figma