
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
Manage your Figma workspace with your agent or terminal.
Find files, organize projects, review access, and manage teams and seats. Connect Figmanage to your AI assistant through MCP, or use the command-line tool yourself.
Figmanage uses your Figma permissions. Admin tasks need admin access.
You need Node.js 18+ and an agent that supports local MCP servers.
1. Add Figmanage. In Claude Code, run:
claude mcp add --transport stdio --scope user figmanage -- npx -y figmanage --mcp
Using Codex, Cursor, VS Code, or Claude Desktop? Generate your client config.
2. Sign in to Figma in Chrome, then ask your agent:
Set up Figmanage, then show my teams and recent files.
Your agent asks before reading your Chrome session. macOS may show a Keychain prompt. Your login is saved locally.
3. Give it a task. Start with one of the examples above.
Some features, such as comments and exports, also need a Figma Personal Access Token. Add it locally with npx -y figmanage login --pat-only, then reconnect MCP. Keep tokens out of chat. See account setup.
npm install -g figmanage
figmanage login
figmanage navigate list-recent-files
Use figmanage --help to find commands, or figmanage doctor if setup needs attention.
Use MCP for tool discovery, or the CLI for automation:
figmanage schema
figmanage navigate list-recent-files --jsonl --no-input
--json or --jsonl. With JSONL, require the final summary and check the exit code.--dry-run checks inputs without sending requests. It does not check live permissions.--progress --jsonl and MCP progress notifications when requested.See the automation guide for output formats and the optional agent skill for workflow recipes.
Use Figmanage to manage files, access, teams, and seats. Use the official Figma MCP for design work. Your agent can pass file links between them; each server has its own login. How they work together.
FAQs
MCP server for managing your Figma workspace from the terminal.
The npm package figmanage receives a total of 0 weekly downloads. As such, figmanage popularity was classified as not popular.
We found that figmanage demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.