figma-to-html

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated Figma export purpose is plausible, but its core conversion path forwards the user’s Figma token and design-derived data to an undocumented third-party/internal Baidu service over plain HTTP. Official Figma API usage is consistent, yet the non-Figma credential/data routing and lack of TLS make the overall footprint disproportionate and high risk.

Confidence: 91%Severity: 89%
Audit Metadata
Analyzed At
May 7, 2026, 03:10 AM
Package URL
pkg:socket/skills-sh/hixuanxuan%2Fbrowser-automation%2Ffigma-to-html%2F@35cf1d70c7051f53a770e457f67c90a1083e0431