T08 · Insecure Dependencies
Warning
- Location
SKILL.md:47- Finding
Unpinned Privileged Third-Party Plugin Handles OAuth-Authenticated Figma Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Figma skill is coherent and not malicious, but it asks users to install and permanently allow a third-party OAuth plugin with broad access to Figma data and write actions.
Install only if you trust ClawLink with the Figma files and actions available to your connected account. Review the plugin source or publisher assurances if available, confirm write actions carefully, and revoke the Figma OAuth connection and remove the plugin when no longer needed.
SKILL.md:47Unpinned Privileged Third-Party Plugin Handles OAuth-Authenticated Figma Data
No suspicious patterns detected.