**Figma Design-to-Code MCP Server | Figma 设计稿转代码 MCP 服务**
The package transmits host identity data and Figma resource identifiers to a third-party analytics host. This is an unconsented data-exfiltration surface during normal conversion use.
Package source references child process execution.
dist/build/plugin/loader.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/build/plugin/loader.jsView on unpkg · L81This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
cli/run.jsView on unpkgPackage source invokes a package manager install command at runtime.
cli/run.jsView on unpkg · L361Source collects local host identity data and sends it to an external endpoint.
dist/build/utils/tj.jsView on unpkg · L1Package declares a runtime dependency whose name matches a Node built-in module.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/interceptor/client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/utils/version-check.jsView on unpkgThis report applies to sloth-d2c@1.0.6-beta.18.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
dist/build/plugin/loader.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/agent/codex-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/interceptor/client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/build/utils/version-check.jsView on unpkgPackage source references dynamic require/import behavior.
dist/build/plugin/loader.jsView on unpkg · L81Package source invokes a package manager install command at runtime.
cli/run.jsView on unpkg · L361This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
cli/run.jsView on unpkgSource collects local host identity data and sends it to an external endpoint.
dist/build/utils/tj.jsView on unpkg · L1Package declares a runtime dependency whose name matches a Node built-in module.
package.jsonView on unpkg · L94