figma-boost-mcp
Warn
Audited by Socket on Aug 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's Figma automation purpose is plausible, but its actual install and credential flow are not proportionate or trustworthy. It replaces Figma's official hosted MCP/OAuth setup with an unverifiable third-party download that receives Figma credentials, so the main risk is supply-chain compromise and credential harvesting rather than confirmed malware.
Confidence: 92%Severity: 91%
Audit Metadata