Back to skill

Security audit

Figma Tw Designer Free

Security checks across malware telemetry and agentic risk

Overview

The skill is broadly a Figma helper, but it asks for powerful agent permissions and documents mutation-style operations beyond its stated read/export/comment purpose.

Review this skill before installing. Use it only for explicit Figma file tasks, provide a least-privilege Figma token when possible, avoid pasting real tokens into chats or files, and do not allow create/modify/delete-style actions unless you intentionally requested them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill claims a narrow read/export/comment scope, but the documentation later introduces generic create/modify/delete style operations through input_params and config_options. This can cause an agent to over-grant capabilities or invoke unintended state-changing behaviors not justified by the declared Figma use case, increasing the risk of unauthorized actions if paired with write/exec tooling.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The metadata declares write capability even though the skill is presented as a read/export/comment helper. Unjustified write access broadens the attack surface because an agent may use filesystem or workspace modification powers during execution, despite the user-facing purpose not requiring them.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger condition is overly broad and can activate this skill for generic design, poster, branding, or creation-related requests far outside its actual Figma file inspection purpose. Over-broad routing increases the chance that an agent selects a tool with exec/write capabilities in inappropriate contexts, leading to unnecessary exposure of local environment data or unintended actions.

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The documentation shows a realistic-looking token string format without an adjacent explicit warning that it is a dummy placeholder and must never be reused. Users or downstream systems may mistakenly copy example secrets into prompts, configs, or logs, normalizing unsafe credential handling and increasing the chance of accidental exposure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.