figma-automation

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill manifest is coherent with its stated purpose (automating Figma via a Composio/Rube MCP toolkit). The primary security concern is that it routes discovery, authentication, and all Figma API calls through a third-party MCP endpoint (https://rube.app/mcp). That design creates a single transitive trust boundary: the MCP can observe or mediate credentials, change tool schemas at runtime, and perform reads/writes on behalf of the user. There is no executable malware or obfuscated payload in the provided content. However, because OAuth flows and tool behavior are mediated remotely and dynamic, this poses a medium supply-chain risk unless the operator explicitly trusts the MCP provider, audits scopes returned during auth, and requires per-action confirmation for write operations. Recommend treating this as suspicious until Rube/Composio's security, token handling, and manifest integrity are independently verified.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 03:42 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Ffigma-automation%2F@1914eba411ef0e19118502913990339d21ea43f7