implement-design

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment describes a coherent, purpose-aligned workflow for implementing Figma designs via the Figma MCP server. It relies on standard design-context APIs and asset retrieval, maps data to an existing design system, and includes validation steps against screenshots. There are no credential harvesting, hidden data exfiltration, or execution-from-URL patterns evident in the fragment. Security risk is moderate due to external dependencies and network calls to a design API, but this is expected for a legitimate design-to-code skill. Overall, the footprint is consistent with its stated purpose and does not exhibit malicious behavior beyond standard supply-chain concerns for remote design assets and tokens.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 03:31 PM
Package URL
pkg:socket/skills-sh/superstone-han%2Fdotfiles%2Fimplement-design%2F@3c15e73cb3f5943f9d366f5e86b63c76f9760388