figma-canon

Warn

Audited by Socket on Oct 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's stated purpose as a Figma safety canon is mostly coherent, but it goes beyond passive guidance by steering the agent toward operational write paths, third-party MCP infrastructure, and other skills. The main risk is credential/data flow integrity: official Figma MCP usage is aligned, but the endorsed figma-console path can forward Figma tokens and session data to non-Figma code/services, which is disproportionate for a read-only knowledge skill.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Oct 2, 2026, 09:41 PM
Package URL
pkg:socket/skills-sh/thiagoxikota%2Ffigma-maxxing%2Ffigma-canon%2F@bf042dc27f364e843b0aa690ae15659d59657dbcbc46e237bdd8e2c88c98c8e4
Security Audit — socket — figma-canon