figma-automation

Warn

Audited by Socket on Jul 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The functional scope matches Figma automation, but the trust chain is inconsistent: it relies on a discontinued Rube MCP endpoint, uses legacy tool naming, and claims a simpler auth model than current Composio documentation supports. The main risk is stale third-party routing of Figma OAuth and design data, not confirmed malware.

Confidence: 88%Severity: 61%
Audit Metadata
Analyzed At
Jul 18, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/rohitg00%2Fbuildwithclaude%2Ffigma-automation%2F@b1215bf82beb6b5e1ad3d684c5228e2daa4305f21ab4d49a1c632e4984c3c0c8
Security Audit — socket — figma-automation