figma-boost-mcp

Warn

Audited by Socket on Aug 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's Figma automation purpose is plausible, but its actual install and credential flow are not proportionate or trustworthy. It replaces Figma's official hosted MCP/OAuth setup with an unverifiable third-party download that receives Figma credentials, so the main risk is supply-chain compromise and credential harvesting rather than confirmed malware.

Confidence: 92%Severity: 91%
Audit Metadata
Analyzed At
Aug 4, 2026, 11:51 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdesign-skills%2Ffigma-boost-mcp%2F@c575dcbb4961e41126517794f8e6fcfad6b078d479bc68170bd96acd279bb816
Security Audit — socket — figma-boost-mcp