Skip to main content

Figma Developer

Automates the conversion of Figma designs into React components, syncing design tokens and streamlining the design-to-code workflow.

Install this skill

or
0/100

Security score

The Figma Developer skill was audited on Feb 9, 2026 and we found 28 security issues across 3 threat categories. Review the findings below before installing.

Categories Tested

Security Issues

medium line 90

Template literal with variable interpolation in command context

SourceSKILL.md
90console.log(` ${tokens.colors.length} colors`)
medium line 91

Template literal with variable interpolation in command context

SourceSKILL.md
91console.log(` ${tokens.typography.length} text styles`)
medium line 92

Template literal with variable interpolation in command context

SourceSKILL.md
92console.log(` ${tokens.spacing.length} spacing values`)
medium line 181

Template literal with variable interpolation in command context

SourceSKILL.md
181console.log(`Found ${iconsFrame.children.length} icons`)
medium line 193

Template literal with variable interpolation in command context

SourceSKILL.md
193await fs.writeFile(`public/icons/${svg.name}.svg`, content)
medium line 194

Template literal with variable interpolation in command context

SourceSKILL.md
194console.log(` ✓ ${svg.name}.svg`)
medium line 246

Template literal with variable interpolation in command context

SourceSKILL.md
246const component = `
medium line 256

Template literal with variable interpolation in command context

SourceSKILL.md
256await fs.writeFile(`components/icons/${componentName}Icon.tsx`, component)
medium line 257

Template literal with variable interpolation in command context

SourceSKILL.md
257console.log(` ✓ ${componentName}Icon.tsx`)
medium line 264

Template literal with variable interpolation in command context

SourceSKILL.md
264return `export { ${componentName}Icon } from './${componentName}Icon'`
medium line 330

Template literal with variable interpolation in command context

SourceSKILL.md
330console.log(` ${component.name}`)
medium line 331

Template literal with variable interpolation in command context

SourceSKILL.md
331console.log(` Key: ${component.key}`)
medium line 332

Template literal with variable interpolation in command context

SourceSKILL.md
332console.log(` Description: ${component.description}`)
medium line 340

Template literal with variable interpolation in command context

SourceSKILL.md
340console.log(` Set: ${setId}`)
medium line 342

Template literal with variable interpolation in command context

SourceSKILL.md
342console.log(` - ${variant.name}`)
medium line 384

Template literal with variable interpolation in command context

SourceSKILL.md
384const component = `
medium line 475

Template literal with variable interpolation in command context

SourceSKILL.md
475return `#${r}${g}${b}`
medium line 487

Template literal with variable interpolation in command context

SourceSKILL.md
487```yaml
medium line 616

Template literal with variable interpolation in command context

SourceSKILL.md
616console.log(`Version: ${previousVersion} → ${currentVersion}`)
medium line 641

Template literal with variable interpolation in command context

SourceSKILL.md
641const types = `
medium line 643

Template literal with variable interpolation in command context

SourceSKILL.md
643${tokens.colors.map(c => `| '${c.name}'`).join('\n ')}
medium line 672

Template literal with variable interpolation in command context

SourceSKILL.md
672throw new Error(`Component not found: ${componentName}`)
medium line 679

Template literal with variable interpolation in command context

SourceSKILL.md
679await fs.writeFile(`components/${componentName}.tsx`, code)
medium line 681

Template literal with variable interpolation in command context

SourceSKILL.md
681console.log(`Synced: ${componentName}`)
medium line 715

Template literal with variable interpolation in command context

SourceSKILL.md
715return `#${r.toString(16).padStart(2, '0')}${g.toString(16).padStart(2, '0')}${b.toString(16).padStart(2, '0')}`
low line 33

Access to .env file

SourceSKILL.md
33# .env
low line 49

Access to .env file

SourceSKILL.md
49accessToken: process.env.FIGMA_ACCESS_TOKEN
low line 24

External URL reference

SourceSKILL.md
241. Go to [Figma Settings](https://www.figma.com/settings)
Scanned on Feb 9, 2026
View Security Dashboard
Installation guide →