figma-design-generate

Fail

Audited by Socket on Mar 5, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The described skill plausibly implements legitimate design-capture functionality (DOM -> Figma). However, it currently requests disproportionately broad host privileges (Bash(*) and Read/Write) and lacks transparency about where captures and authentication tokens are sent. Primary risks: (1) credential forwarding or storage by an opaque intermediary MCP service, (2) sensitive-data capture from production UIs with no redaction controls, and (3) potential for arbitrary host command execution due to shell permissions. I do not find definitive malicious code in the description, but the supply-chain and privilege posture warrant a medium security risk. Mitigations: enforce least privilege (limit to specific, audited commands), require explicit user consent before starting servers or capturing production sites, document auth flows and endpoints, and provide redaction options and retention/ownership policies for captured data.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 5, 2026, 08:15 AM
Package URL
pkg:socket/skills-sh/petbrains%2Fmvp-builder%2Ffigma-design-generate%2F@baac7185c676d1f2d71c46583703c43a2647c83e