figma-content-operator
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
AnomalyAnomalyassets/figwright.windows.mcp.json
LOWAnomalyLOW
assets/figwright.windows.mcp.json
No explicit malicious code is present in this JSON fragment; however, it configures automatic runtime download/execute of a third-party npm package via cmd.exe + npx (with -y). This is a meaningful supply-chain execution risk requiring integrity/allowlisting/lockfile-style protections in the broader system, and should be reviewed with the referenced package and host execution controls.
Confidence: 70%Severity: 62%
Audit Metadata