**Figma Design-to-Code MCP Server | Figma 设计稿转代码 MCP 服务**
A D2C conversion transmits local account and host fingerprints together with Figma file and node identifiers to an external beacon service. This is not limited to a local service or required Figma API call.
Package source references child process execution.
dist/build/plugin/loader.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/build/plugin/loader.jsView on unpkg · L81This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
cli/run.jsView on unpkgPackage source invokes a package manager install command at runtime.
cli/run.jsView on unpkg · L361Source collects local host identity data and sends it to an external endpoint.
dist/build/utils/tj.jsView on unpkg · L1Package declares a runtime dependency whose name matches a Node built-in module.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/interceptor/client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/utils/version-check.jsView on unpkgThis report applies to sloth-d2c-mcp@1.0.6-beta.18.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
dist/build/plugin/loader.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/interceptor/client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/utils/version-check.jsView on unpkgPackage source references dynamic require/import behavior.
dist/build/plugin/loader.jsView on unpkg · L81Package source invokes a package manager install command at runtime.
cli/run.jsView on unpkg · L361This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
cli/run.jsView on unpkgSource collects local host identity data and sends it to an external endpoint.
dist/build/utils/tj.jsView on unpkg · L1Package declares a runtime dependency whose name matches a Node built-in module.
package.jsonView on unpkg · L94