figma-automation

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated Figma automation purpose and uses an official same-org Composio/Rube endpoint, so it does not look malicious. However, it routes Figma auth and content through a third-party managed MCP gateway rather than direct Figma APIs, and the setup claim about needing no keys/tokens is somewhat incomplete. Risk is medium due to intermediary data flow and external side effects, not because of overt malware behavior.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 13, 2026, 04:38 PM
Package URL
pkg:socket/skills-sh/Oceanjackson1%2FClaude-Skill%2Ffigma-automation%2F@1914eba411ef0e19118502913990339d21ea43f7
Security Audit — socket — figma-automation