figma-driven-nextjs

Warn

Audited by Socket on Feb 27, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
skills.json

The fragment presents notable supply-chain risks: (1) a non-standard dependencies format that could cause install-time misinterpretation or concealment of dependencies, and (2) a postinstall script that can execute arbitrary shell commands. These two issues create a trust and integrity risk that warrants immediate review of both the dependencies structure and the contents/behavior of scripts/install.sh before publishing or consuming this package. If scripts/install.sh is benign and the dependencies field is corrected to a valid object, risk is substantially reduced.

Confidence: 59%Severity: 62%
SecurityMEDIUM
SKILL.md

The manifest presents a coherent automation path for a Figma-driven Next.js bootstrap and design-system scaffolding. However, the installation model—downloading and executing remote scripts via npx from GitHub without visible integrity checks or per-action confirmations—poses a meaningful supply-chain risk and could enable arbitrary code execution if the source is compromised. Treat as SUSPICIOUS to HIGH-RISK until artifacts are pinned, signed, and auditable, with explicit user confirmation at each major step.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 02:03 AM
Package URL
pkg:socket/skills-sh/Zekiwest%2Fagent-skills%2Ffigma-driven-nextjs%2F@8c8266a0ce279b7402eafbc82734fca450086d04