figma-automation

Warn

Audited by Socket on Jun 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities match Figma automation, but data and OAuth credentials are routed through a Composio/Rube intermediary rather than direct Figma APIs, and the referenced Rube endpoint appears discontinued/stale. This is not confirmed malware, but it carries medium risk from third-party credential brokering and remote service trust.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Jun 23, 2026, 10:02 AM
Package URL
pkg:socket/skills-sh/yashas-30%2FNYX%2Ffigma-automation%2F@dbd46c6fdb7021b1adf63ac30104ac6033f7be3d8fcb3835df0eb706364204db
Security Audit — socket — figma-automation