figma-automation
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s Figma-focused capabilities are proportionate to its purpose, and there is no direct evidence of malware, exfiltration commands, or dangerous installers. However, it routes all activity through a deprecated third-party MCP service, misstates setup/auth requirements, and relies on a stale endpoint instead of Figma’s official MCP path, creating medium trust and data-flow risk.
Confidence: 90%Severity: 60%
Audit Metadata