Back to skill

Security audit

Figma设计集成-免费版

Security checks across malware telemetry and agentic risk

Overview

This Figma skill is not malicious, but its instructions are too broad and partly inconsistent for a tool that connects to a third-party API and can access workspace design data.

Review before installing. Use this only for Figma browsing, reading, exporting, comments, and version history. Do not rely on it for generic document conversion or file processing, and avoid connecting sensitive Figma workspaces unless you are comfortable with MorphixAI acting as the API broker. Prefer a least-privilege Figma account or workspace connection.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill declares a read-only free edition, then later instructs the agent to use generic `input_params` and `config_options` for create/modify/import/reset operations. This creates dangerous ambiguity about permitted actions and can cause an agent to attempt unintended state-changing operations against connected services or local configuration, exceeding the documented trust boundary.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The document first states that posting/deleting comments and other write-like actions are unsupported, but immediately follows with broad execution guidance implying creation and modification are possible. Contradictory operational guidance is hazardous because agentic systems may privilege the later, more general instructions and perform unauthorized or policy-violating actions.

Vague Triggers

High
Confidence
90% confidence
Finding
The trigger condition says to use this skill whenever file processing, document conversion, format conversion, or content extraction is needed, which is far broader than the skill's actual Figma-only scope. Overbroad routing criteria can cause the agent to invoke a Figma-connected external API in unrelated contexts, increasing the chance of unnecessary workspace data exposure or misuse of connected credentials.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The overview promotes the tool as 'safe and reliable' but does not clearly warn that it accesses Figma workspace data via an external API broker (MorphixAI). Missing disclosure reduces informed consent and may lead users to expose team/project metadata, design contents, comments, or exported assets to third-party processing without understanding the data flow.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.