Back to skill

Security audit

Figma Toolkit Free

Security checks across malware telemetry and agentic risk

Overview

This Figma skill appears mostly purpose-aligned, but it asks for broad read/write/exec authority and includes vague create/modify/delete and callback behavior without clear limits.

Review this skill before installing. Use it only with Figma files and tokens you are comfortable exposing to the agent and its Figma tooling, keep output directories limited to your project, and require explicit confirmation before any command execution, package install, callback URL use, or create/modify/delete operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
The skill is presented as a narrowly scoped free Figma design/export toolkit, but its documented behavior expands to generic create/query/modify/delete operations. This scope inflation can cause an agent to apply the skill to actions outside the user’s expected intent, increasing the risk of unauthorized file or system changes.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill declares exec alongside read/write for a personal-use Figma toolkit without meaningful limitation or justification. Unrestricted command execution materially broadens the attack surface, enabling arbitrary local commands, package execution, and potential data loss or host compromise if the agent follows malicious or ambiguous prompts.

Vague Triggers

Medium
Confidence
77% confidence
Finding
The examples and trigger conditions are broad and underspecified, telling the agent to identify a need, load modules, and execute operations without precise guardrails. In an AI skill context, vague invocation logic increases the chance of overbroad execution, misuse of powerful tools, and unsafe interpretation of user requests.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill combines export, exec, and token-dependent external service access but does not clearly warn users about system-side effects, network access, or sensitive data handling. This weakens informed consent and makes accidental exposure of design data, credentials, or local files more likely during normal use.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.