Back to skill

Security audit

Figma

Security checks across malware telemetry and agentic risk

Overview

This Figma skill is a documentation-based helper with disclosed, purpose-aligned local preference storage and Figma automation guidance.

Before installing, understand that this skill may remember Figma preferences in ~/Clawic/data/figma/. Review or delete those files if you do not want persistent context, use backups before migrating old preference folders, and get participant consent before recording prototype tests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Low
Confidence
88% confidence
Finding
The skill explicitly instructs moving user data from older directories into `~/Clawic/data/figma/` without any warning, confirmation step, backup guidance, or validation of what is being moved. In an agent context, filesystem-modifying instructions can lead to unintended data loss, overwrites, or migration of sensitive files if path handling is wrong or overbroad.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The guidance recommends recording testing sessions as a best practice but does not mention obtaining participant consent, notifying users of recording, or complying with privacy requirements. In a design/prototyping skill, this omission can lead teams to capture personally identifiable information, screen contents, voice, or behavioral data without appropriate disclosure or authorization.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to read and later write user-local files under ~/Clawic/data/figma without any user-facing notice, consent, or clear bounds on what persistent data may be stored. This creates a privacy and integrity risk because the agent can silently ingest prior context and persist new data across sessions, which may surprise users and expose sensitive preferences or project details.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.