figma-core-workflow-b

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
references/download-exported-images.md

The code implements a plausible image-export workflow and shows no direct indicators of malware. However, deriving a filesystem path from unsanitized nodeId values creates a potential path traversal and arbitrary file overwrite vulnerability if nodeIds are attacker-controlled. The implementation should validate node IDs, sanitize filename components, resolve and verify that the final path remains under outputDir, and validate fetch responses before writing.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:45 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Ftons-of-skills-marketplace%2Ffigma-core-workflow-b%2F@089cca76e700e5b304ac699bac84cb5b97ddf4e5cbf68d9da33e454651ad3463
Security Audit — socket — figma-core-workflow-b