**Figma Design-to-Code MCP Server | Figma 设计稿转代码 MCP 服务**
Normal D2C use sends telemetry containing local account and device metadata to a remote analytics endpoint. No install-time attack was identified.
Package source references child process execution.
dist/build/plugin/loader.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/build/plugin/loader.jsView on unpkg · L81Source collects local host identity data and sends it to an external endpoint.
dist/build/utils/tj.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
cli/run.jsView on unpkgPackage source invokes a package manager install command at runtime.
cli/run.jsView on unpkg · L361Package declares a runtime dependency whose name matches a Node built-in module.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/utils/utils.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/interceptor/client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/utils/version-check.jsView on unpkgThis report applies to sloth-d2c@1.0.6-beta.20.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
dist/build/plugin/loader.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/utils/utils.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/interceptor/client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/utils/version-check.jsView on unpkgPackage source references dynamic require/import behavior.
dist/build/plugin/loader.jsView on unpkg · L81Source collects local host identity data and sends it to an external endpoint.
dist/build/utils/tj.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
cli/run.jsView on unpkg · L361This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
cli/run.jsView on unpkgPackage declares a runtime dependency whose name matches a Node built-in module.
package.jsonView on unpkg · L94