Atlas / MCP servers / pactortester / Figma Context Cached

Figma Context CachedCAUTION

mcp/pactortester/figma-context-cached

Cache‐enabled Figma Context MCP with persistent disk caching to reduce API rate limits and improve performance.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
5 5r · 0w · 0d
Transport
sse · stdio · streamable-http
License
MIT
Stars
78
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English Version: README_EN.md

基于 Figma Context MCP 的增强版本,通过本地持久化缓存显著减少对 Figma API 的请求次数,从而缓解速率限制问题,提升稳定性与响应速度。

该版本特别适合 免费 Figma 账号、高频上下文请求、以及 Cursor / MCP 客户端 场景。

✨ 特性

  • ✅ 支持 Figma 文件内容本地缓存
  • ✅ 显著减少 API 请求次数,缓解速率限制
  • ✅ 可配置缓存有效期(TTL)
  • ✅ 支持自定义缓存目录
  • ✅ `figma_prepare_file` 工具:智能准备和缓存 Figma 文件
  • ✅ 支持 nodeId 检查:确保指定的节点存在于缓存中
  • ✅ 支持强制刷新:通过 forceRefresh 参数强制获取最新设计数据
  • ✅ 智能下载路径:图片下载默认保存到系统下载文件夹(支持 Windows/macOS/Linux)
  • ✅ 优化的 LLM 调用引导:自动引导正确的工具调用顺序
  • ✅ 完全兼容原有 MCP 接口与调用方式
  • ✅ `list_cache` 工具:查看缓存状态和统计信息
  • ✅ `cleanup_cache` 工具:清理过期和损坏的缓存文件
  • ✅ 自动缓存清理:定时清理过期缓存,保持磁盘空间整洁
  • ✅ LRU 内存缓存:智能内存缓存,避免重复磁盘 I/O
  • ✅ 节点级别缓存:内存中缓存已解析的节点数据
  • ✅ 可选缓存加密:支持 AES-256-CBC 加密保护敏感设计数据
  • ✅ 适用于 Cursor 等 MCP 客户端

🚀 快速开始(30 秒上手)

1. 获取 Figma API Key

访问 Figma 开发者设置 创建 Personal Access Token。

2. 配置 MCP(以 Cursor 为例)

在 Cursor 的 MCP 配置文件中添加:

{
"mcpServers": {
"Figma-Context-MCP-Cached": {
"command": "npx",
"args": [
"-y",
"@pactortester/figma-mcp-cached",
"--stdio",
"--figma-api-key=YOUR_FIGMA_API_KEY",
"--figma-caching={\"ttl\":{\"value\":7,\"unit\":\"d\"}}"
]
}
}
}

3. 开始使用

在 Cursor 中直接粘贴 Figma 链接,AI 会自动:

  1. 调用 figma_prepare_file 准备文件
  2. 调用 get_figma_data 获取设计数据
💡 提示:首次请求会从 Figma API 获取数据并缓存,后续请求直接从本地缓存读取,速度提升 10 倍以上!

📦 Figma 缓存机制说明(重要)

⚠️ 请在设计相对稳定或已定稿后再启用缓存功能

本 MCP 默认支持对 Figma API 返回结果进行缓存(可配置 TTL),以减少 API 请求次数、提升响应速度并避免触发 Figma 的限流策略。

✅ 缓存的优势

  • 显著提升 MCP 响应速度
  • 降低 Figma API 调用频率
  • 适合已定稿或低频变更的设计文件

⚠️ 潜在风险(请务必注意)

由于缓存机制的存在:

  • 当 Figma 页面或组件发生更新时
  • 在缓存未过期(TTL 内)
  • MCP 可能仍
Read from source at commit 0c5185deab8dOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add figma-mcp-cached --env FIGMA_API_KEY=${FIGMA_API_KEY} --env FIGMA_FILE_KEY=${FIGMA_FILE_KEY} --env FIGMA_OAUTH_TOKEN=${FIGMA_OAUTH_TOKEN} -- npx -y @pactortester/[email protected]
claude-desktop
{
  "mcpServers": {
    "figma-mcp-cached": {
      "command": "npx",
      "args": [
        "-y",
        "@pactortester/[email protected]"
      ],
      "env": {
        "FIGMA_API_KEY": "${FIGMA_API_KEY}",
        "FIGMA_FILE_KEY": "${FIGMA_FILE_KEY}",
        "FIGMA_OAUTH_TOKEN": "${FIGMA_OAUTH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (5)

5 read · 0 write · 0 destructive.

ToolRiskDescription
cleanup_cachereadClean up expired and corrupted cache files. This tool removes cache files that have exceeded their TTL (Time To Live) and any corrupted cache entries. Use this to free up disk space and maintain cache health.
download_figma_imagesreadDownload SVG and PNG images used in a Figma file based on the IDs of image or icon nodes
figma_prepare_filereadIMPORTANT: When a user provides a Figma URL, you MUST call this tool FIRST before calling get_figma_data. This tool prepares the Figma file by checking if it
get_figma_datareadGet comprehensive Figma file data including layout, content, visuals, and component information. IMPORTANT: If the user provided a Figma URL, you MUST call figma_prepare_file FIRST before calling this tool. This tool expects the file to be already prepared.
list_cachereadList and display the current cache status including cached files, total size, cache directory, and TTL configuration. Use this tool to inspect what Figma files are currently cached and manage cache storage.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
README.md:4
<img src="./docs/logo.png" alt="Figma Context MCP Logo" width="200" style="border-radius: 50%; border: 3px solid #e0e0e0; padding: 10px; background-color: #ffffff;">
MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
README_EN.md:4
<img src="./docs/logo.png" alt="Figma Context MCP Logo" width="200" style="border-radius: 50%; border: 3px solid #e0e0e0; padding: 10px; background-color: #ffffff;">
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/tests/integration.test.ts:73
const parsed = yaml.load(content);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/tools/download-figma-images-tool.ts:4
import { FigmaService } from "../../services/figma.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/tools/download-figma-images-tool.ts:5
import { Logger } from "../../utils/logger.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@figma/rest-api-spec, @modelcontextprotocol/sdk, @types/yargs, cross-env, dotenv, express, js-yaml, remeda
Why it matters. 29 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:43
访问 [Figma 开发者设置](https://www.figma.com/developers/api#access-tokens) 创建 Personal Access Token。
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README_EN.md:41
Visit [Figma Developer Settings](https://www.figma.com/developers/api#access-tokens) to create a Personal Access Token.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 0c5185deab8dfull audit observations/trust-audit/mcp-server/pactortester__figma-context-cached.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-080c5185deab8dCAUTIONB89first audit
06

Questions

What is the Figma Context Cached MCP server?

Cache‐enabled Figma Context MCP with persistent disk caching to reduce API rate limits and improve performance.

What tools does Figma Context Cached expose?

5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Figma Context Cached safe to connect to an agent?

With care. The audit graded it B (89/100) and found 8 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Figma Context Cached need?

It reads FIGMA_API_KEY, FIGMA_FILE_KEY and FIGMA_OAUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Figma Context Cached run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @pactortester/figma-mcp-cached at 1.2.0.

How current is this page?

The grade is for one exact copy of the source (0c5185deab8d), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement