figma-automation

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s Figma-focused capabilities are proportionate to its purpose, and there is no direct evidence of malware, exfiltration commands, or dangerous installers. However, it routes all activity through a deprecated third-party MCP service, misstates setup/auth requirements, and relies on a stale endpoint instead of Figma’s official MCP path, creating medium trust and data-flow risk.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Sep 4, 2026, 03:05 PM
Package URL
pkg:socket/skills-sh/new-career-begin%2Fqueryweaver%2Ffigma-automation%2F@ccedcf09fce2c0b76adce074ba3e09ed0b8c85c0f61e27d8b91f60c9c355e1a6
Security Audit — socket — figma-automation