figma-generate-personal-token

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core purpose matches its behavior—obtaining a Figma token via Figma's own site—but it does so by consuming raw account credentials, passing them through a third-party browser automation tool, generating a longest-expiry token, and enabling all permissions. There is no obvious off-platform exfiltration or fake endpoint, so this is not confirmed malware, but the scope and credential handling are broader than necessary for a token-management skill.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Apr 8, 2026, 09:44 AM
Package URL
pkg:socket/skills-sh/ClubMediterranee%2Fai-core%2Ffigma-generate-personal-token%2F@8f2226290d0ff46dd43326f1b1ef93dca2115028