
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
figma-mcp-server
Advanced tools
A simple MCP server for Figma
Install the server
git clone https://github.com/planetabhi/figma-mcp-server.git
cd figma-mcp-server
bun i
Create a .env
file and set the FIGMA_API_KEY
to your Figma API key.
FIGMA_API_KEY=
To generate a new personal access token, log in to your Figma account, then from the top-left menu, head to Settings, click on the security tab, find the Personal access tokens section, and click Generate new token to open the configuration modal where you can set the expiration and scopes before clicking Generate token.
List descriptions and parameters from all available tools
bun list-tools
# Find node path
which node
# Get the absolute path of the MCP server
realpath mcpServer.js
{
"mcpServers": {
"figma-mcp-server": {
"command": "<absolute_path_to_node>",
"args": ["<absolute_path_to_mcpServer.js>"]
}
}
}
To try it out in Claude Desktop, first enable the
get_file_nodes
tool from the tools list. Copy a design node link from a Figma file, then paste it into Claude Desktop prompt. It will return the design node data and other information.
.gemini
directory (if it doesn't exist)mkdir -p ~/.gemini
settings.json
fileecho '{
"mcpServers": {
"figma-mcp-server": {
"command": "<absolute_path_to_node>",
"args": ["mcpServer.js"],
"cwd": "<absolute_path_to_working_directory>",
"env": {
"FIGMA_API_KEY": "your_figma_api_key_here"
},
"trust": true
}
}
}' > ~/.gemini/settings.json
export GEMINI_API_KEY="your_gemini_api_key_here"
npx https://github.com/google-gemini/gemini-cli
/mcp
to list all tools/mcp desc
to show server and tool descriptions/mcp schema
to show tool parameter schemas/mcp nodesc
to hide descriptions⋛⋋( ⊙◊⊙)⋌⋚
FAQs
A simple MCP server for Figma
The npm package figma-mcp-server receives a total of 162 weekly downloads. As such, figma-mcp-server popularity was classified as not popular.
We found that figma-mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.