Back to skill

Security audit

figma-to-mobile

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Figma-to-mobile purpose, but it needs review because SVG export can fetch unvalidated URLs outside the declared Figma API scope and installation pulls an unpinned dependency.

Review before installing. Use a least-privilege Figma token, do not paste it into chat, approve project scans only for repositories you are comfortable indexing, decline feedback logging for sensitive corrections, and prefer a version that pins dependencies and validates SVG download hosts.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned Runtime Dependency Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/figma_fetch.py:486
Finding

Unrestricted Retrieval of API-Provided SVG URLs

Content
View full analysis
dict: """Export nodes as SVG via Figma API. Returns {node_id: svg_string}.""" ids_param = ",".join(node_ids) url = f"https://api.figma.com/v1/images/{file_key}?ids={ids_param}&format=svg" headers = {"X-Figma-Token": token} _rate_limit() resp = requests.get(url, headers=headers, timeout=30) resp.raise_for_status() data = resp.json() results = {} images = data.get("images", {}) for nid, svg_url in images.items(): if svg_url: try: svg_resp = requests.get(svg_url, timeout=30) svg_resp.raise_for_status() results[nid] = svg_resp.text ``` ### Technical Analysis The initial request is correctly directed to `https://api.figma.com` and carries the Figma token in the `X-Figma-Token` header. However, each URL returned in the response’s `images` object is subsequently fetched without validation. The code does not verify: - That the secondary URL uses HTTPS. - That its hostname belongs to an approved Figma CDN domain. - That DNS resolution does not produce a loopback, private, link-local, or reserved address. - That redirects remain on approved destinations. - That the response has an expected SVG content type. - That the response size remains within a safe limit. The Figma token is not forwarded to the secondary URL, which limits direct credential exposure. Nevertheless, the secondary request can use the Skill host’s network position to reach destinations unavailable to an external attacker. It also exceeds the declared network permission in `SKILL.md`, which lists only `api.figma.com`. Exploitation requires control or manipulation of the API-provided image URL, such as ...[truncated 1696 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (60)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 49)May include surrounding context.

md
## Setup

> ⚠️ **Figma Token** — Set the `FIGMA_TOKEN` environment variable.
> Generate one at Figma → Avatar → Settings → Security → Personal Access Tokens.
>
> **Do not paste your token into chat** — chat messages may be logged.
> Set it via your shell profile or system environment variables:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
## Setup

> ⚠️ **Figma Token** — Set the `FIGMA_TOKEN` environment variable.
> Generate one at Figma → Avatar → Settings → Security → Personal Access Tokens.
>
> **Do not paste your token into chat** — chat messages may be logged.
> Set it via your shell profile or system environment variables:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/figma_fetch.py (reported line 531)May include surrounding context.

python
## Setup

> ⚠️ **Figma Token** — Set the `FIGMA_TOKEN` environment variable.
> Generate one at Figma → Avatar → Settings → Security → Personal Access Tokens.
>
> **Do not paste your token into chat** — chat messages may be logged.
> Set it via your shell profile or system environment variables:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 103)May include surrounding context.

md
## Requirements

- Python 3.8+ with `requests` package
- Figma Personal Access Token (free)

## Feedback & Issues

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code clearly works with the Figma REST API and does implement multi-node comparison, which partially aligns with the description. However, its primary behavior is limited to retrieving, simplifying, diffing, and exporting Figma design data. There is no code generation logic for any mobile UI framework, no local filesystem resource scanning beyond optional JSON output writing, and no feedback-log correction mechanism. Additionally, it provides SVG export as an extra undeclared capability. Because the declared primary purpose is end-to-end Figma-to-mobile-code conversion, while the actual code is a lower-level Figma extraction/comparison utility, this is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code chunk’s primary purpose is an Android layout XML analyzer for local resources, likely for pattern learning or statistics collection. This is materially different from the declared purpose of converting Figma designs into mobile UI code. While the description mentions local resource scanning as part of a broader pipeline, this specific code does not implement any Figma-related ingestion or any code generation behavior; it only analyzes existing Android layout XML files. That constitutes a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose centers on transforming Figma designs into mobile UI code across multiple frameworks, implying Figma link handling, REST API access, design interpretation, and code generation. The supplied code does none of that. It is a local Android project scanner utility that reads Gradle settings files, identifies modules, and checks whether they contain resources or source directories worth scanning. While local resource scanning is mentioned in the description, this snippet is only a generic Android module resolver and lacks any Figma-specific behavior or code-generation functionality. Therefore, the code chunk's primary purpose is materially different from the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description is about transforming Figma designs into mobile UI code across several frameworks. This code chunk does not interact with Figma, accept or process Figma URLs, compare design frames, or generate UI code. Its actual purpose is an Android-only local scanner that inspects project modules and resources, analyzes dependencies and layouts, indexes colors/strings/text styles/drawables, and assigns semantic labels based on themes and naming. While the description mentions local resource scanning as part of the broader Figma workflow, this chunk by itself implements only the Android scanning subsystem and none of the core advertised conversion behavior, making the description materially inaccurate for this code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code does not interact with Figma links, the Figma REST API, design conversion, code generation, multi-frame comparison, or feedback-log correction. Its primary function is a local static analyzer for Android source files that discovers custom view classes in a project. While local resource/project scanning could be a supporting detail in a broader UI-generation system, this specific chunk is focused on Android custom view detection and is materially different from the declared purpose of converting Figma designs to mobile UI code. Therefore this chunk represents a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code is a generic scanning framework for local project analysis across platforms like Android/iOS/Flutter. It defines report dataclasses, abstract scanner interfaces, and a scan pipeline for discovering modules, scanning them, building resource indices, and adding semantic labels. There is no implementation for calling the Figma API, parsing Figma designs, accepting a Figma link, or emitting mobile UI code in any target framework. While the description mentions local resource scanning, this chunk only covers that supporting infrastructure and lacks the core advertised behavior, making the declared purpose materially inaccurate for this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code chunk’s behavior is materially different from the declared purpose. Rather than converting Figma designs into mobile UI code, it scans an existing local Flutter project directory (lib/, pubspec.yaml, .arb files, assets) to extract resources and widget metadata. This local scanning could be a supporting component in a larger design-to-code system, but in isolation this chunk neither consumes Figma input nor produces Compose/XML/SwiftUI/UIKit/Flutter output. The actual primary purpose here is Flutter resource discovery/indexing, which is undeclared as the skill’s main behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose centers on taking Figma designs and generating mobile UI code via the Figma API. This code chunk does not interact with Figma links, the Figma REST API, code generation, frame comparison, or feedback-log correction. Instead, it performs local filesystem scanning of iOS assets. While local resource scanning is mentioned in the description, this specific chunk is only an asset scanner and by itself is not representative of the declared primary function. Its actual behavior is a supporting utility for iOS asset discovery, which is materially different from the stated end-user capability if considered in isolation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description centers on transforming Figma designs into mobile UI code. This code chunk does not parse Figma links, call the Figma API, compare frames, generate UI code, or apply feedback-log corrections. Instead, it scans the local filesystem to detect whether a project appears to be an iOS/Xcode or Swift Package Manager project. That behavior is materially different from the declared purpose, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose centers on turning Figma designs into mobile UI code across several frameworks. The supplied code does not parse Figma links, call the Figma REST API, generate Compose/XML/SwiftUI/UIKit/Flutter code, compare frames, or apply feedback-log corrections. Its actual function is a local scanner for iOS colors and localization resources. While local resource scanning is mentioned in the description as a supporting capability, this chunk by itself implements only that narrow scanner behavior and lacks the primary design-to-code functionality, making the description materially inaccurate for this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose centers on transforming Figma designs into mobile UI code. This code chunk does not interact with Figma, parse design links, or generate any UI code. Instead, it scans an existing local iOS codebase for resources and views, builds lookup indices, and labels color semantics. While the description mentions local resource scanning as part of the broader skill, this chunk’s actual primary behavior is only the scanner component, with none of the claimed Figma conversion pipeline present. That is a material description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose centers on Figma-driven design-to-code generation for multiple mobile UI frameworks. In contrast, this code only scans local .swift files under a directory, skipping common build/test folders, and extracts existing project metadata such as colors, localization keys, and view/class definitions. While 'local resource scanning' is mentioned in the description, this snippet does not participate in Figma fetching or UI code generation and instead implements a distinct source-analysis function. That is a material behavior mismatch rather than a minor supporting detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code chunk does not implement Figma design ingestion or conversion to mobile UI code. Instead, it performs static analysis of local Swift source files to discover iOS view definitions. While local resource scanning is mentioned in the description, this specific behavior is not clearly in service of Figma conversion within the provided chunk and is materially different from the declared primary purpose. The code neither consumes a Figma link nor calls the Figma REST API, nor does it generate Compose/XML/SwiftUI/UIKit/Flutter output. Therefore, the description does not accurately represent this code chunk's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description centers on a Figma-to-mobile-code conversion skill. The actual code chunk does not implement or exercise Figma ingestion, REST API calls, frame comparison, code generation, or feedback-log correction. Instead, it is exclusively an integration/unit test file for a local project scanning subsystem, especially Android resource/module scanning and platform detection. While local resource scanning is mentioned in the description, this code’s primary purpose is materially different and much narrower: validating a scanner, not generating UI code from Figma. Therefore the description does not accurately represent the supplied code chunk.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

The instruction to read the current file and output changed lines with context can cause the agent to disclose local file contents back into the conversation, even when only a small edit was requested. In a project-aware skill with broad project-root read access, this pattern increases the risk of prompt-driven source extraction or accidental disclosure of sensitive code fragments, especially if users or adversarial content steer the agent toward confidential files.

Content

Scanner excerpt · SKILL.md (reported line 222)May include surrounding context.

md
Continue iterating until the user is satisfied.

**Iteration output rule:**
- If the file has already been written to disk → read the current file, apply only the minimal patch, output just the changed lines with clear context (file path + line range). Do NOT regenerate the whole file.
- If the code only exists in the conversation (not written to disk) → output only the changed snippet with a comment indicating where it replaces (e.g., `// replaces lines 12-18 in activity_main.xml`). Do NOT repeat the entire file.
- Only regenerate the full file if the user explicitly asks (e.g., "重新生成完整文件", "show me the full file").

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

The skill instructs persistent logging of every user correction to feedback-log.md, including before/after snippets, to 'learn and improve over time.' In a code-generation context, those snippets can contain proprietary source, API endpoints, secrets accidentally pasted by users, or sensitive business logic, creating an unnecessary long-lived local memory store that expands exposure beyond the immediate task.

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
Continue iterating until the user is satisfied.

**Iteration output rule:**
- If the file has already been written to disk → read the current file, apply only the minimal patch, output just the changed lines with clear context (file path + line range). Do NOT regenerate the whole file.
- If the code only exists in the conversation (not written to disk) → output only the changed snippet with a comment indicating where it replaces (e.g., `// replaces lines 12-18 in activity_main.xml`). Do NOT repeat the entire file.
- Only regenerate the full file if the user explicitly asks (e.g., "重新生成完整文件", "show me the full file").

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/error-handling.md (reported line 7)May include surrounding context.

md
Tell the user:

> I need a Figma Personal Access Token to fetch the design.
> ⚠️ **Do not paste it into this chat** — chat messages may be logged.
> Set it as an environment variable and restart.
> Get one at: Figma → avatar → Settings → Security → Personal Access Tokens

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/error-handling.md (reported line 10)May include surrounding context.

md
> I need a Figma Personal Access Token to fetch the design.
> ⚠️ **Do not paste it into this chat** — chat messages may be logged.
> Set it as an environment variable and restart.
> Get one at: Figma → avatar → Settings → Security → Personal Access Tokens
>
>   Windows: `setx FIGMA_TOKEN "figd_xxx"`
>   macOS/Linux: add `export FIGMA_TOKEN="figd_xxx"` to ~/.zshrc

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/error-handling.md (reported line 18)May include surrounding context.

md
> I need a Figma Personal Access Token to fetch the design.
> ⚠️ **Do not paste it into this chat** — chat messages may be logged.
> Set it as an environment variable and restart.
> Get one at: Figma → avatar → Settings → Security → Personal Access Tokens
>
>   Windows: `setx FIGMA_TOKEN "figd_xxx"`
>   macOS/Linux: add `export FIGMA_TOKEN="figd_xxx"` to ~/.zshrc

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/generation-rules.md (reported line 4)May include surrounding context.

md
# Code Generation Rules
> Referenced by SKILL.md Step 3. Read this file before generating code.

## Output Rules (absolute — never break these)

**Write boundary — generated code stays in conversation until confirmed:**
- Output all generated code in the conversation first, as text with filename headers (e.g. `📄 activity_main.xml`).

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/xml-patterns.md (reported line 30)May include surrounding context.

  • Note: This is a strong signal, not an absolute rule. If the design clearly shows a single static page with tab-like labels that are purely decorative, adjust accordingly. When unsure, ASK.
xml
<!-- Standard Tab + ViewPager2 structure -->
<com.google.android.material.tabs.TabLayout
    android:id="@+id/tabLayout"
    android:layout_width="0dp"

Static analysis

No suspicious patterns detected.