figma-content-operator

Warn

Audited by Socket on Aug 6, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/figwright.windows.mcp.json

No explicit malicious code is present in this JSON fragment; however, it configures automatic runtime download/execute of a third-party npm package via cmd.exe + npx (with -y). This is a meaningful supply-chain execution risk requiring integrity/allowlisting/lockfile-style protections in the broader system, and should be reviewed with the referenced package and host execution controls.

Confidence: 70%Severity: 62%
Audit Metadata
Analyzed At
Aug 6, 2026, 01:29 AM
Package URL
pkg:socket/skills-sh/lintendo%2FAxhub-Skills%2Ffigma-content-operator%2F@cee9cf0e1fdb1a6fcd574ccea76152758c49731d20239dedbeed3bcc122c79f3
Security Audit — socket — figma-content-operator