cc-figma-component

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core behavior is largely coherent for Figma component generation and mainly targets official Figma APIs, but risk is elevated by transitive prerequisite skills, raw credential-file access, unpinned `npx rimraf` execution, and optional dynamic code execution guidance. This is not confirmed malicious and shows no clear third-party exfiltration path in the provided text, but it exceeds low-risk benign documentation/automation patterns.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 25, 2026, 03:15 AM
Package URL
pkg:socket/skills-sh/nvillapiano%2Fcomponent-contracts-figma%2Fcc-figma-component%2F@5d33fba9eec7c0b6e5f4127f96c156c9b358f0af