Missing User Warnings
Low
- Confidence
- 88% confidence
- Finding
- The skill explicitly tells the agent to download and directly use assets from the Figma MCP server, including localhost-served assets, without requiring user awareness or confirmation about network access and local resource retrieval. While this is part of the intended workflow, it can still cause unintended access to local or remote resources and normalize blind trust of externally supplied asset URLs.
