Figma PilotSAFE
MCP that let AI agents control Figma through code execution
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@youware-labs/figma-pilot-mcp) [](https://opensource.org/licenses/MIT)
AI agents control Figma through code execution.
English | 中文
Demo
OpenAI Landing Page
Prompt: "Create an OpenAI style landing page introducing the upcoming GPT 5.3 release on Figma"
[](./assets/openai.mp4)
Manus Design System
Prompt: "Generate a Manus design system components based on the screenshot, on Figma"
[](./assets/manus.mp4)
Design Philosophy
This project is inspired by Anthropic's Code execution with MCP approach.
Instead of exposing dozens of individual MCP tools (which bloat the context window and slow down agents), figma-pilot provides only 3 tools:
The AI writes code to interact with Figma. This means:
- 90%+ fewer tokens in tool definitions
- Batch operations - modify 100 elements in one call
- Data filtering - filter results before returning to context
- Complex workflows - loops, conditionals, error handling
Quick Start
Prerequisites
- Node.js >= 18
- Figma Desktop app
- An MCP-compatible AI client (Claude Desktop, Claude Code, Cursor, Codex, etc.)
1. Install MCP Server
# Claude Code claude mcp add figma-pilot -- npx @youware-labs/figma-pilot-mcp # Other MCP clients - add to your MCP config:
{
"mcpServers": {
"figma-pilot": {
"command": "npx",
"args": ["@youware-labs/figma-pilot-mcp"]
}
}
}Con
05271cf6553aOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add shared -- npx -y @figma-pilot/[email protected]
{
"mcpServers": {
"shared": {
"command": "npx",
"args": [
"-y",
"@figma-pilot/[email protected]"
]
}
}
}Exposed tools (18)
9 read · 8 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
accessibility | read | Check accessibility issues and optionally fix them (WCAG compliance) |
append | write | Move element(s) into a container frame |
bind-token | read | Bind a design token to an element property |
create | write | Create elements in Figma |
create-token | write | Create a new design token |
create-variants | write | Create component variants |
delete | destructive | Delete elements from Figma |
export | read | Export element as image |
figma_get_api_docs | read | Get detailed API documentation for figma_execute. ALWAYS call this BEFORE writing complex figma_execute code to ensure correct syntax! The docs reference the figma-pilot skill for advanced patterns. Look for |
figma_status | read | Check connection status to Figma plugin. Call this first to verify the plugin is running. |
instantiate | write | Create an instance of a component |
list-components | read | List available components in the Figma file |
modify | write | Modify existing elements in Figma |
query | read | Query information about elements (by ID, name, or selection) |
serve | write | Run persistent bridge server for Figma plugin connection |
status | read | Check connection status to Figma plugin |
sync-tokens | write | Sync design tokens between Figma and JSON file |
to-component | read | Convert element to a component |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
delete
zip -r "../../${OUTPUT_DIR}/${ZIP_NAME}" \@types/bun, typescript
citty, @types/bun, typescript
@modelcontextprotocol/sdk, @figma-pilot/shared, @types/bun, @types/node, typescript
@figma/plugin-typings, esbuild, typescript
typescript
assets/manus.gif
assets/manus.mp4
assets/openai.gif
assets/openai.mp4
Gates applied: no_behavioural_pass.
05271cf6553afull audit observations/trust-audit/mcp-server/youware-labs__figma-pilot.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 05271cf6553a | SAFE | B | 89 | first audit |
Questions
What is the Figma Pilot MCP server?
MCP that let AI agents control Figma through code execution
What tools does Figma Pilot expose?
18 in total: 9 read-only, 8 that write, and 1 that can delete or overwrite (delete). Every one is listed on this page with its risk.
Is Figma Pilot safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Figma Pilot need?
No credential environment variables were found in its source, so it appears to need none.
How does Figma Pilot run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @figma-pilot/shared at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (05271cf6553a), read on 2026-10-07. The repository is watched and re-audited when it changes.