implement-design

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the skill's described footprint is coherent with its stated purpose of translating Figma designs into code within a controlled MCP-driven workflow. There are no alarming patterns such as download-execute chains, credential harvesting, or external exfiltration portrayed. The only notable consideration is ensuring that localhost asset handling and MCP-bound endpoints remain restricted to trusted environments to prevent leakage or tampering. If used as described, this appears benign and purpose-aligned for design-to-code automation within a design-system-driven project.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/figma%2Fmcp-server-guide%2Fimplement-design%2F@51523284d53fb7815acb784c7e347ffd5418c4f4