Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- scripts/verify-motion.mjs:96
Security audit
Security checks across malware telemetry and agentic risk
This Figma import skill is purpose-aligned and disclosed: it uses read-only Figma access to freeze assets and motion data into local HyperFrames files.
Before installing, expect this skill to read Figma files your token can access and to create local project files under media/cache/component paths. Use a read-only Figma token with the narrow scopes described, review the skill update prompt before approving it, and be aware that connector-assisted motion or shader work may require separate authorization or native exports.
64/64 vendors flagged this skill as clean.
Detected: suspicious.dangerous_exec