Context Leakage
- Category
- Data Exfiltration
- Confidence
- 96% confidence
- Finding
The skill instructs the agent to use the currently selected node from the Figma desktop app when no URL is provided, which can pull design context from a local application state the user did not explicitly identify in the prompt. That creates a real context-leakage risk: an attacker can socially engineer the agent into exfiltrating screenshots, metadata, or assets from whichever confidential design happens to be selected.
- Content
md When using the `figma-desktop` MCP and the user has NOT provided a URL, the tools automatically use the currently selected node from the open Figma file in the desktop app. **Note:** Selection-based prompting only works with the `figma-desktop` MCP server. The remote server requires a link to a frame or layer to extract context. The user must have the Figma desktop app open with a node selected. ### Step 2: Fetch Design Context
