Back to Home
oabolade icon

figma_mcp_server_actor

Verified Safe

by oabolade

Overview

Enables AI assistants to interact with Figma designs and projects using natural language commands via a Model Context Protocol (MCP) server.

Installation

Run Command
npm start

Environment Variables

  • FIGMA_ACCESS_TOKEN
  • FIGMA_OAUTH_CLIENT_ID
  • FIGMA_OAUTH_CLIENT_SECRET

Security Notes

The server securely handles Figma Personal Access Tokens (PATs) and provides placeholders for OAuth 2.0. Input parameters for API calls are validated (e.g., `enum` for formats). The core functionality involves calling predefined JavaScript functions (tool handlers) rather than arbitrary code execution, mitigating direct injection risks. Broad CORS `Access-Control-Allow-Origin: *` is set, which is standard for a public API but should be considered when embedding in restricted environments. Overall, no critical security vulnerabilities like `eval` or hardcoded secrets were found in the provided code.

Similar Servers

Stats

Interest Score32
Security Score8
Cost ClassMedium
Avg Tokens1000
Stars1
Forks0
Last Update2025-11-23

Tags

FigmaAI AssistantMCPDesignAPI Wrapper