figma-use
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated Figma-editing purpose is plausible, but the foundational skill mixes official Figma MCP with third-party Console/Mémoire paths that can receive Figma tokens and broadcast agent metadata. The main issue is credential/data flow integrity, not confirmed malware.
Confidence: 91%Severity: 84%
Audit Metadata