**Figma Design-to-Code MCP Server | Figma 设计稿转代码 MCP 服务**
During MCP/CLI operations, the package gathers local account and host identifiers and sends them with tool metadata to an external analytics service. This is concrete runtime data exfiltration, though not install-time execution.
Package source references child process execution.
dist/build/plugin/loader.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
cli/run.jsView on unpkg · L361Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/run.jsView on unpkgPackage source references dynamic require/import behavior.
dist/build/server.jsView on unpkg · L809Source collects local host identity data and sends it to an external endpoint.
dist/build/utils/tj.jsView on unpkg · L1Package declares a runtime dependency whose name matches a Node built-in module.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/utils/utils.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/interceptor/client.jsView on unpkgPackage source references child process execution.
dist/build/plugin/loader.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/utils/utils.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/interceptor/client.jsView on unpkgPackage source invokes a package manager install command at runtime.
cli/run.jsView on unpkg · L361Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/run.jsView on unpkgPackage source references dynamic require/import behavior.
dist/build/server.jsView on unpkg · L809Source collects local host identity data and sends it to an external endpoint.
dist/build/utils/tj.jsView on unpkg · L1Package declares a runtime dependency whose name matches a Node built-in module.
package.jsonView on unpkg · L94