figma-design

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose is coherent for a Figma extraction skill, and the official Figma MCP and direct REST API paths are proportionate. The main concern is the optional fallback to a third-party MCP that may receive the Figma API key, creating unnecessary credential-forwarding and supply-chain risk for a task that can be performed with official Figma tooling.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Mar 23, 2026, 06:33 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Ffigma-design%2F@e811f70763083f6bf90e8f2336792b82a2917522