Back to skill

Security audit

figma

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Figma API helper that uses Maton OAuth and includes clear controls around account connection, credentials, and write actions.

Before installing, understand that this skill can access Figma data available to your connected account and can post or delete comments, reactions, and dev resources if you approve those actions. Use read-only scopes where possible, confirm the exact file and payload before any write, and avoid raw API-key mode unless the Maton CLI cannot be used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
80% confidence
Finding
The skill states variables are not available through this connection, but nearby passthrough semantics and later resource links to variable endpoints can still cue an agent to attempt those calls. This inconsistency weakens guardrails by blurring unsupported capability boundaries, which is risky because variables endpoints may expose broader design-system data or trigger confusing permission/error handling.

Description-Behavior Mismatch

Medium
Confidence
80% confidence
Finding
The skill states variables are not available through this connection, but nearby passthrough semantics and later resource links to variable endpoints can still cue an agent to attempt those calls. This inconsistency weakens guardrails by blurring unsupported capability boundaries, which is risky because variables endpoints may expose broader design-system data or trigger confusing permission/error handling.

VirusTotal

53/53 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.