Back to skill

Security audit

figma

Security checks across malware telemetry and agentic risk

Overview

This Figma import skill is purpose-aligned and disclosed: it uses read-only Figma access to freeze assets and motion data into local HyperFrames files.

Before installing, expect this skill to read Figma files your token can access and to create local project files under media/cache/component paths. Use a read-only Figma token with the narrow scopes described, review the skill update prompt before approving it, and be aware that connector-assisted motion or shader work may require separate authorization or native exports.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/verify-motion.mjs:96