figma

Warn

Audited by Runlayer on Feb 21, 2026

Risk Level: MEDIUM
Scan Summary
Max Score
78%
Files
5
Flagged
5
Chunks
6
Flagged Files (5)
LICENSE.txtHIGH
78.3%

Malicious tool definition detected

Tool: LICENSE.txt [1/2] Description: Apache License Version 2.0, January 2004 http://www.apache.org/licenses/ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION 1.

5. Submission of Contributions.

SKILL.mdHIGH
78.3%

Malicious tool definition detected

Tool: SKILL.md Description: --- name: figma description: Use the Figma MCP server to fetch design context, screenshots, variables, and assets from Figma, and to translate Figma nodes into production code.

agents/openai.yamlHIGH
78.3%

Malicious tool definition detected

Tool: agents/openai.yaml Description: interface: display_name: "Figma" short_description: "Use Figma MCP for design-to-code work" icon_small: "./assets/figma-small.svg" icon_large: "./assets/figma.png" default_prompt: "Use Figma MCP to inspect the target design and translate it into implementable UI decisions."

references/figma-mcp-config.mdHIGH
78.3%

Malicious tool definition detected

Tool: references/figma-mcp-config.md Description: # Figma MCP config reference Use this snippet to register the Figma MCP server in `~/.codex/config.toml` as a streamable HTTP server with bearer auth pulled from your env.

references/figma-tools-and-prompts.mdHIGH
78.3%

Malicious tool definition detected

Tool: references/figma-tools-and-prompts.md Description: # Figma MCP tools and prompt patterns Quick reference for the Figma MCP toolset, when to use each tool, and prompt examples to steer output toward your stack.

Audit Metadata
Max File Score
78%
Classification
UNKNOWN_SERVER
Files Scanned
5
Files Flagged
5
Chunks Analyzed
6
Analyzed
Feb 21, 2026, 06:00 PM
Security Audit — runlayer — figma