figma-use

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated Figma-editing purpose is plausible, but the foundational skill mixes official Figma MCP with third-party Console/Mémoire paths that can receive Figma tokens and broadcast agent metadata. The main issue is credential/data flow integrity, not confirmed malware.

Confidence: 91%Severity: 84%
Audit Metadata
Analyzed At
Sep 4, 2026, 06:21 AM
Package URL
pkg:socket/skills-sh/memi-design%2Fdesign-skills%2Ffigma-use%2F@8636ac3a49c63c58d1507f57b32a8f2f9ea5fde30c01fb795789ffd7c6215a63
Security Audit — socket — figma-use