Atlas / MCP servers / timholden / Figma

FigmaCAUTION

mcp/timholden/figma-2

Model Context Protocol server implementation for Figma API

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
11 6r · 4w · 1d
Transport
sse · stdio
License
—
Stars
150
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that provides integration with Figma's API through Claude and other MCP-compatible clients. Currently supports read-only access to Figma files and projects, with server-side architecture capable of supporting more advanced design token and theme management features (pending Figma API enhancements or plugin development).

Project Status

Current Progress

  • ✅ Core Implementation: Successfully built a TypeScript server following the Model Context Protocol (MCP)
  • ✅ Claude Desktop Integration: Tested and functional with Claude Desktop
  • ✅ Read Operations: Working get-file and list-files tools for Figma file access
  • ✅ Server Architecture: Caching system, error handling, and stats monitoring implemented
  • ✅ Transport Protocols: Both stdio and SSE transport mechanisms supported

Potential Full Functionality

The server has been designed with code to support these features (currently limited by API restrictions):

  • Variable Management: Create, read, update, and delete design tokens (variables)
  • Reference Handling: Create and validate relationships between tokens
  • Theme Management: Create themes with multiple modes (e.g., light/dark)
  • Dependency Analysis: Detect and prevent circular references
  • Batch Operations: Perform bulk actions on variables and themes

With Figma plugin development or expanded API access, these features could be fully enabled.

Features

  • 🔑 Secure authentication with Figma API
  • 📁 File operations (read, list)
  • 🎨 Design system management
  • Variable creation and management
  • Theme creation and configuration
  • Reference handling and validation
  • 🚀 Performance optimized
  • LRU caching
  • Rate limit handling
  • Connection pooling
  • 📊 Comprehensive monitoring
  • Health checks
  • Usage statistics
  • Error tracking

Prerequisites

  • Node.js 18.x or higher
  • Figma access token with appropriate permissions
  • Basic understandi
Read from source at commit afeb891d4cc5OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add figma-mcp-server --env FIGMA_ACCESS_TOKEN=${FIGMA_ACCESS_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "figma-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "FIGMA_ACCESS_TOKEN": "${FIGMA_ACCESS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (11)

6 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
create_referencewriteCreate a reference between variables
create_themewriteCreate a theme with variable mode configurations
create_variableswriteCreate variables in a Figma file
delete_variablesdestructiveDelete variables from a Figma file
get-filereadGet details of a Figma file
get_file_detailsreadGet detailed information about a specific Figma file
list-filesreadList files in a Figma project
list_componentsreadList all components in a Figma file
search_filesreadSearch for Figma files by name or keywords
update_variableswriteUpdate existing variables in a Figma file
validate_referencesreadCheck for circular references and validate dependencies
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

MEDIUMInventory / provenance · inv.binary · CWE-1104
.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_variables
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/debug, axios, debug, dotenv, lru-cache, node-fetch, zod
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha afeb891d4cc5full audit observations/trust-audit/mcp-server/timholden__figma-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07afeb891d4cc5CAUTIONB86first audit
06

Questions

What is the Figma MCP server?

Model Context Protocol server implementation for Figma API

What tools does Figma expose?

11 in total: 6 read-only, 4 that write, and 1 that can delete or overwrite (delete_variables). Every one is listed on this page with its risk.

Is Figma safe to connect to an agent?

With care. The audit graded it B (86/100) and found 7 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Figma need?

It reads FIGMA_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Figma run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as figma-mcp-server at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (afeb891d4cc5), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement