figma-to-code
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core design-to-code functionality is benign and well-aligned, with no credential access or exfiltration. However, the skill unnecessarily recommends installing an unverified third-party skill hub, creating a transitive supply-chain trust risk that does not belong in a narrowly scoped Figma-to-code skill.
Confidence: 90%Severity: 62%
Audit Metadata