figlooCAUTION
Chrome extension + local MCP server that lets coding agents like Claude Code and Codex read Figma designs through the web UI with view access: walk layers, inspect properties, take screenshots, export assets. No Figma API; never edits the design.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 繁體中文
Figloo is a local Figma bridge and design context layer for coding agents. It lets an agent explore the design you have open in your browser, starting from your selection: walk the layers around it, read layout and visual properties exactly as Figma's inspection panel shows them, take screenshots, export icons and images, and save snapshots of whole screens to implement from. It is a Chrome extension plus a local MCP server, and it only reads what Figma's web UI shows: no Figma REST API, official Figma MCP, Figma plugin, or private internal state. It may change the view and selection, but it never edits the design.
Why Figloo
- View access is enough. Figma's REST API and its official MCP server set their limits by seat: a View or Collab seat gets up to 6 calls a month (REST API, MCP server, as of October 2026). Figloo reads the Figma tab you already have open, so it needs no token or paid seat, and it has no monthly quota.
- It starts from what you point at. The agent begins at the layers you selected, and every call reads a bounded part of the file instead of scanning all of it.
- Read once, implement from the snapshot.
snapshot_layerreads a whole screen, up to 2,000 layers, and saves it. The agent then looks up values, summarizes the colors, text styles, and spacing it uses, and compares it with the previous snapshot, without touching Figma again. - Local. There is no Figloo server or account, and the bridge listens only on
127.0.0.1. See Privacy and security.
If your team has Dev or Full seats, Figma's own MCP server reads the file directly and is the more direct route. Figloo is for engineers with view access who want their coding agent to work from the design in front of them.
How it works
Coding agent ──stdio (MCP)──▶ Figl
16fd4dfed9ebOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add protocol --env FIGLOO_ACCEPT_FILE_KEY=${FIGLOO_ACCEPT_FILE_KEY} -- npx -y @figloo/[email protected]{
"mcpServers": {
"protocol": {
"command": "npx",
"args": [
"-y",
"@figloo/[email protected]"
],
"env": {
"FIGLOO_ACCEPT_FILE_KEY": "${FIGLOO_ACCEPT_FILE_KEY}"
}
}
}
}Exposed tools (15)
15 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
capture | read | |
explore_page | read | |
export_asset | read | |
export_assets | read | |
get_anchor | read | |
get_neighbors | read | |
get_status | read | |
get_visual_neighbors | read | |
inspect_nodes | read | |
list_pages | read | |
map_tokens | read | |
query_snapshot | read | |
release_context | read | |
snapshot_layer | read | |
summarize_snapshot | read |
Trust audit
CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (23)
console.log(`Figloo pairing\n token: ${config.token}\n port: ${config.port}\n config: ${configPath()}\n\nPaste the token and port into the Figloo extension options page.`);if (distance <= NEAR_DELTA_E && alpha <= 0.05) found.push(match(token, "near", `ΔE ${distance.toFixed(1)}`, 2 + distance));"such as a color difference (ΔE, where about 2.3 is just noticeable), an alpha, a pixel, or a weight. Each instance name comes with project components whose names share its words. " +
expect(mapped.colors.find((c) => c.value === "#D5D5D5")!.matches[0]).toMatchObject({ token: "--color-border-subtle", match: "near", difference: expect.stringMatching(/^ΔE 0\.\d$/) });expect(output.colors.find((c) => c.value === "#D5D5D5")!.matches[0]).toMatchObject({ token: "--color-border-subtle", match: "near" });figma-icon-export.zip
.node-version
tests/skill-eval/skills
const serialized = new Function(`return (${installExportCapture.toString()})`)() as typeof installExportCapture;const ZIP = readFileSync(resolve(import.meta.dirname, "../../../tests/fixtures/export/figma-icon-export.zip"));
const FIXTURES = resolve(import.meta.dirname, "../../../tests/fixtures/projects");
expect(errorOf(await call("query_snapshot", { snapshot: "../../etc/passwd" })).code).toBe("SNAPSHOT_NOT_FOUND");const web = resolve(import.meta.dirname, "../../../tests/fixtures/projects/web");
const DOC = resolve(import.meta.dirname, "../../../docs/mcp-tools.md");
expect(mapped.colors.find((c) => c.value === "#D5D5D5")!.matches[0]).toMatchObject({ token: "--color-border-subtle", match: "near", difference: expect.stringMatching(/^ΔE 0\.\d$/) });@types/chrome, esbuild, happy-dom, typescript, vitest
ws, zod, @types/node, @types/ws, typescript, vitest
esbuild, playwright
zod, typescript, vitest
Figloo runs on your machine. The MCP server listens only on `127.0.0.1` and accepts only the Figloo extension, identified by its pinned ID and the pairing token. Figloo has no server or account of its
Please report a vulnerability privately, not in a public issue: open the repository's [Security tab](https://github.com/g761007/figloo/security) and choose "Report a vulnerability". Describe what an a
- Besides the WebSocket, the server answers two HTTP requests, `GET /holder` and `POST /handover`, which other Figloo servers on the same machine use to hand the extension over between agent sessions.
The MCP server loads only in a new agent session. Tell the user to start one, open a Figma design file in the browser, and ask the agent to call Figloo's `get_status`. It should report the extension a
Gates applied: no_behavioural_pass.
16fd4dfed9ebfull audit observations/trust-audit/mcp-server/g761007__figloo.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 16fd4dfed9eb | CAUTION | C | 75 | first audit |
Questions
What is the figloo MCP server?
Chrome extension + local MCP server that lets coding agents like Claude Code and Codex read Figma designs through the web UI with view access: walk layers, inspect properties, take screenshots, export assets. No Figma API; never edits the design.
What tools does figloo expose?
15 in total: 15 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is figloo safe to connect to an agent?
With care. The audit graded it C (75/100) and found 23 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does figloo need?
It reads FIGLOO_ACCEPT_FILE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does figloo run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @figloo/protocol at 0.6.0.
How current is this page?
The grade is for one exact copy of the source (16fd4dfed9eb), read on 2026-10-07. The repository is watched and re-audited when it changes.