figma-developer

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/asset-export.md

The code implements a legitimate Figma asset-export workflow and shows no clear malicious behavior. It reads a Figma token as expected, communicates with Figma and its image URLs, and writes generated assets and source files. The main security risks are raw SVG-to-TSX injection, insufficient validation of component names, filename collisions, and unverified network content. Use sanitized SVGR output, validate identifiers, enforce uniqueness, verify expected Figma hosts and HTTPS, and review generated files before building.

Confidence: 96%Severity: 54%
AnomalyLOW
references/component-generation.md

The fragment is legitimate component-generation documentation and does not show malware or unauthorized data exfiltration. It contains two security weaknesses: untrusted style values are inserted into generated source without escaping, and componentName is used directly in an output path, creating a potential path traversal risk. Inputs should be validated, generated code should escape or constrain all interpolated values, and output paths should be resolved and restricted to the intended directory.

Confidence: 97%Severity: 54%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:52 AM
Package URL
pkg:socket/skills-sh/oakoss%2Fagent-skills%2Ffigma-developer%2F@9b1da60a86af350c6ae7d46242e1c305182f8bb017e156541cac6b2b07b236bb
Security Audit — socket — figma-developer