figma-catalog-import

Fail

Audited by Snyk on Jul 24, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). These URLs point to a personal GitHub project that explicitly instructs users to download a prebuilt plugin ZIP from the repository's "releases/latest" (a personal GitHub release can contain arbitrary binaries), so obtaining and running that archive without verifying the build/source is a security risk.

Issues (1)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 24, 2026, 01:26 PM
Issues
1
Security Audit — snyk — figma-catalog-import