implement-design
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Overall, the skill's described footprint is coherent with its stated purpose of translating Figma designs into code within a controlled MCP-driven workflow. There are no alarming patterns such as download-execute chains, credential harvesting, or external exfiltration portrayed. The only notable consideration is ensuring that localhost asset handling and MCP-bound endpoints remain restricted to trusted environments to prevent leakage or tampering. If used as described, this appears benign and purpose-aligned for design-to-code automation within a design-system-driven project.
Confidence: 75%Severity: 75%
Audit Metadata