Agent skill

Figma Typings Audit

by awdr74100 in awdr74100/figwright

Upgrade @figma/plugin-typings and absorb what the new version exposes.

MITAuto-check passedDevelopment

Install Figma Typings Audit

skills CLI
$ npx skills add awdr74100/figwright --skill figma-typings-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install awdr74100/figwright figma-typings-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/awdr74100/figwright.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/figma-typings-audit .claude/skills/figma-typings-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
figma-typings-audit
GitHub stars
1k
Token cost
~3.3k tokens
SKILL.md length
1,431 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Upgrade @figma/plugin-typings and absorb what the new version exposes.

  • Works in 9 steps: Resolve versions → Get the authoritative diff → Classify every hunk → …
  • The user wants @figma/plugin-typings updated
  • SKILL.md covers Stage 0 — Resolve versions, Stage 1 — Get the…, Stage 2 — Classify every hunk and Stage 3 — Map the diff onto…, plus 5 more sections
  • Calls pnpm, npm and npx

What it does

Figma Typings Audit is an agent skill from awdr74100/figwright. Upgrade @figma/plugin-typings and absorb what the new version exposes. Diffs the .d.ts between the installed and the target version (that package ships no changelog), sorts the changes into breakage / new API / silently-added fields, maps each onto the sandbox handlers, the hand-written Zod mirrors in shared, and the tool registry — then bumps the package and builds whatever the user picks. Use whenever the user wants @figma/plugin-typings updated or audited, or asks what a new plugin-typings version would break…

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Forms and validation and Changelog and release notes. It works with Figma, Zod, Model Context Protocol and npm. The repository describes itself as: Free, two-way Figma MCP server. Turn designs into framework-aware code, and push code back to the canvas. Works with Claude Code, Cursor, Codex, and any MCP client. The licence is MIT.

When your agent uses it

  • The user wants @figma/plugin-typings updated
  • Asks what a new plugin-typings version would break
  • Newly enable — including a Renovate bump PR for that package

Example prompts

  • “/figma-typings-audit”

Requirements

  • Node.js

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Resolve versions
  2. Get the authoritative diff
  3. Classify every hunk
  4. Map the diff onto the repo
  5. Sandbox typecheck (only if Stage 2 found bucket 1)
  6. Decide, then upgrade
  7. Report, then let the user pick
  8. Implement the picks
  9. Hand off the live verification

What it can do on your machine

Read from SKILL.md and the folder at commit 7e39435. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • npm
    • npx
    • tsc
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, npm, npx and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Figma Typings Audit loads about 3.3k tokens when it runs. Until then it costs about 151 tokens; SKILL.md has 1,431 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~151
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from awdr74100/figwright at commit 7e39435, republished under its MIT licence (© awdr74100). 1,431 words, ~3,331 tokens.

Download SKILL.mdSave it as .claude/skills/figma-typings-audit/SKILL.md (or your agent's skills folder).
name
figma-typings-audit
description
Upgrade @figma/plugin-typings and absorb what the new version exposes. Diffs the .d.ts between the installed and the target version (that package ships no changelog), sorts the changes into breakage / new API / silently-added fields, maps each onto the sandbox handlers, the hand-written Zod mirrors in shared, and the tool registry — then bumps the package and builds whatever the user picks. Use whenever the user wants @figma/plugin-typings updated or audited, or asks what a new plugin-typings version would break or newly enable — including a Renovate bump PR for that package.

Absorbing a @figma/plugin-typings release into Figwright, end to end: audit → upgrade → implement what's worth having.

One hard ordering constraint: diff before upgrading. The audit compares the installed version against the target, so upgrading first destroys the baseline. (Recoverable — the old version is in git history and npm pack can still fetch it — but don't create the problem.)

Target version: whatever the user named, otherwise the latest on npm.

Stage 0 — Resolve versions

bash
grep '@figma/plugin-typings' packages/plugin/package.json          # the declared range
grep '"version"' packages/plugin/node_modules/@figma/plugin-typings/package.json  # what is installed
npm view @figma/plugin-typings version                              # latest
npm view @figma/plugin-typings versions --json                      # how many releases are being skipped

Compare against the installed version, not the declared range — a caret range can already be satisfied by something newer than what the lockfile pinned.

If installed and target are equal, say so and stop. Don't spend tokens on the rest.

Stage 1 — Get the authoritative diff

There is no other source. figma/plugin-typings ships no CHANGELOG and no GitHub Releases (the releases API returns an empty array), and its commit messages are content-free (1.132.0, Release v1.132 updates). The .d.ts diff is the only ground truth.

Work in the session scratchpad directory ($SCRATCH below):

bash
cd "$SCRATCH" && mkdir -p typings-audit && cd typings-audit
npm pack @figma/plugin-typings@<installed> @figma/plugin-typings@<target> --pack-destination .
for v in <installed> <target>; do
  mkdir -p "$v" && tar -xzf "figma-plugin-typings-$v.tgz" -C "$v" --strip-components=1
done
diff -rq <installed> <target>            # which files differ at all — start here
diff -u <installed>/package.json <target>/package.json
diff -u <installed>/index.d.ts <target>/index.d.ts

diff -rq first, so the set of changed files is observed rather than assumed. Every file it names has to be accounted for — including plugin-api-standalone.d.ts, whose trailing export { ... } is one enormous single line where a removed symbol is easy to miss.

index.d.ts declares the figma global, fetch and timers — small, but high blast radius. package.json looks irrelevant and isn't: its devDependencies.prettier explains formatting noise. When that version moves, the .d.ts diff fills with reflowed unions and extends clauses that mean nothing. Check it before reading a single hunk.

Normalize before diffing the .d.ts

Never classify hunks straight out of diff -u. Reformat both versions with the target's own formatter first, so what survives is guaranteed to be semantic:

bash
mkdir -p norm
for v in <installed> <target>; do
  for f in plugin-api.d.ts plugin-api-standalone.d.ts; do cp "$v/$f" "norm/$v.$f"; done
done
cp <target>/.prettierrc norm/.prettierrc          # the package ships its own config
npx --yes prettier@<version from target package.json devDeps> --write "norm/*.d.ts"
diff -u norm/<installed>.plugin-api.d.ts norm/<target>.plugin-api.d.ts
diff -u norm/<installed>.plugin-api-standalone.d.ts norm/<target>.plugin-api-standalone.d.ts

Watch prettier's own per-file output: the target files should report unchanged. That confirms you picked the right formatter version, and turns "the noise is upstream reformatting" from a guess into an observation.

Classify from these normalized diffs. plugin-api.d.ts is the one that matters — packages/plugin/tsconfig.json sets types: ["@figma/plugin-typings"], whose index.d.ts references it — and standalone serves as a cross-check that nothing was missed.

Measured on 1.134.0 → 1.135.0: 328 raw lines collapsed to 32, all of them one change. Never estimate the size of a release from raw diff line count — 1.134.0 was smaller (228 lines) and carried three real buckets.

When the jump spans several releases, diff the two endpoints; the cumulative effect is what matters. Go release-by-release only to attribute a specific change to a version.

Stage 2 — Classify every hunk

Drop hunks that are JSDoc-only (comment/example churn, no signature change) — the file is mostly documentation and these dominate the line count without meaning anything.

Sort the rest into three buckets:

  1. Breaking — a removed symbol, a narrowed type (optional → required, union → smaller union), a changed signature, or a newly-added @deprecated. Look at - lines first.
  2. New API — a new method, node type, enum member, or namespace. A new capability, so a candidate for a new tool or a new argument on an existing one.
  3. New field on an existing type — an added property on something Figwright already reads (Paint, Effect, TextStyle, a node interface…). ⚠️ The dangerous bucket. No compiler will ever flag it and the read path will keep silently omitting the dimension. It is this repo's recurring bug class: a multi-dimensional Figma property collapsed to one field or dropped on the way out.

Stage 3 — Map the diff onto the repo

The three source trees have completely different exposure. Don't treat them alike:

TreeCoupling to typingsWho catches a break
packages/plugin/src/**Real. The only tree that calls figma.* and loads the global types (tsconfig.json → types: ["@figma/plugin-typings"])tsc
packages/plugin/ui/**None — the Vue panel never touches the Figma APIn/a, skip
packages/shared/src/**★ None — and that's the trap. serialized-node.ts, styles.ts, queries.ts are hand-written Zod mirrors of Figma shapes; shared/tsconfig.json never loads typingsNobody but this audit
  • Bucket 1 — grep the affected symbols under packages/plugin/src/ (handlers, serializer.ts, traverse.ts, reveal.ts). Confirm with Stage 4 rather than reasoning about it.
  • Bucket 3 — for each added field, check whether the Zod mirror in packages/shared/src/ carries it, and whether serializer.ts or handlers/get-design-context.ts projects it. A miss here is a real fidelity gap with every gate green.
  • Bucket 2 — check coverage against packages/mcp/src/tools/registry.ts (ALL_TOOL_SPECS is the authority on the tool count; prose in READMEs is hand-written and stale).

Stage 4 — Sandbox typecheck (only if Stage 2 found bucket 1)

Type-check the real sandbox sources against the new typings without touching the repo. Never overwrite the copy in node_modules — pnpm hard-links it into the global store, so writing there corrupts the store for every project on the machine.

Write $SCRATCH/typings-audit/tsconfig.probe.json:

json
{
  "compilerOptions": {
    "target": "ES2023",
    "module": "ESNext",
    "moduleResolution": "Bundler",
    "lib": ["ES2023", "DOM", "DOM.Iterable"],
    "strict": true,
    "noUncheckedIndexedAccess": true,
    "noImplicitOverride": true,
    "noFallthroughCasesInSwitch": true,
    "noUnusedLocals": true,
    "noUnusedParameters": true,
    "exactOptionalPropertyTypes": true,
    "esModuleInterop": true,
    "forceConsistentCasingInFileNames": true,
    "isolatedModules": true,
    "verbatimModuleSyntax": true,
    "resolveJsonModule": true,
    "skipLibCheck": true,
    "noEmit": true,
    "types": []
  },
  "files": ["./<target>/index.d.ts"],
  "include": [
    "<REPO_ROOT>/packages/plugin/src/**/*.ts",
    "<REPO_ROOT>/packages/plugin/protocol/**/*.ts"
  ]
}

Expand <REPO_ROOT> to git rev-parse --show-toplevel — the tsconfig lives outside the repo, so those entries have to be absolute. Never hard-code a machine-specific path into a committed file.

types: [] keeps the installed (old) typings out; the files entry pulls the new ones in via its /// <reference path="./plugin-api.d.ts" />. Module resolution still works because it is anchored to each source file's own location, not to the tsconfig's.

bash
./node_modules/.bin/tsc -p "$SCRATCH/typings-audit/tsconfig.probe.json"

Run the same probe against the installed version first. A clean baseline is what makes a failure on the new version mean something.

Show full SKILL.md (578 more words)Show less

Stage 5 — Decide, then upgrade

  • Anything in bucket 1 → stop and report. Present what breaks and what it would cost to absorb, and let the user decide. Never upgrade past a breaking change on your own initiative.
  • Otherwise upgrade and prove the tree is still green:
bash
pnpm -C packages/plugin add -D @figma/plugin-typings@^<target>
pnpm typecheck && pnpm lint && pnpm format:check && pnpm knip && pnpm build && pnpm test

This is the first step that writes to the repo — packages/plugin/package.json and pnpm-lock.yaml. Everything before it was read-only.

Stage 6 — Report, then let the user pick

Report in 繁體中文台灣用語, ordered by consequence:

  1. 會壞掉的 — symbol, call sites under packages/plugin/src/, probe verdict. Say so explicitly when the list is empty.
  2. 靜默漏接風險 (bucket 3) — added field → the shared mirror that lacks it → the projection that would need to carry it. Flag that no gate catches these.
  3. 新能力 (bucket 2) — one line each: what Figma now exposes, and the smallest change that would surface it.

Report only what the diff and the probe actually showed. Don't pad with plausible-sounding changes, and never claim a live verification you didn't run.

Then AskUserQuestion (multi-select) over the items from 2 and 3.

Stage 7 — Implement the picks

Choosing where a new capability lands is the part worth thinking about:

  • Follow the real usage path, not the closest-sounding tool name. Ask when an agent would actually want this value, and put it on the tool that is already being called at that moment.
  • Keep the semantics honest. Editor-wide state does not belong inside a per-node object — make it a sibling field, and say so in the JSDoc.
  • Smallest change that closes the gap: a field on an existing result < a new argument < a new tool. The tool count is already large; a new tool needs to earn itself.
  • A new read dimension usually touches four places: the Zod schema in packages/shared/src/, the sandbox handler in packages/plugin/src/handlers/, the tool description in packages/mcp/src/tools/ (it is the LLM's only spec — fix it if it misreports the shape), and a test.
  • exactOptionalPropertyTypes is on: assign optional fields conditionally (if (x !== undefined) result.x = x), never result.x = undefined.
  • Guard editor-dependent APIs on figma.editorType rather than try/catch, so reads that deliberately don't assert the editor stay non-throwing in FigJam / Dev Mode without swallowing real errors.
  • Several handlers have no test file at all. If the one you touch is bare, write the test file.
  • Attack your own test. Break the guard on purpose and confirm the test goes red; a test that passes either way is decoration. Then put it back.

Re-run all six gates when done.

Stage 8 — Hand off the live verification

Unit tests don't prove a read path works against real Figma. Before claiming anything:

  • The MCP server runs the built dist → pnpm build, then the user reconnects the MCP server.
  • The plugin sandbox runs the dist it loaded at launch → the user must close and reopen the plugin inside Figma. Reconnecting MCP alone is not enough.
  • Some values can't be verified automatically at all — anything reflecting editor UI state (an open timeline, a playhead, a viewport) can be read but not staged through the plugin API. Design a contrast instead of a single reading: measure once in the neutral state, have the user set up the state, then measure again. A lone "field is absent" is unreadable — it can't distinguish "the plugin never reloaded" from "the state genuinely isn't there".
  • Building probe material on the canvas writes to the user's file. Ask first, and delete it after.

Report what was actually run. If the live step didn't happen, say that.

© awdr74100, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/figma-typings-audit of awdr74100/figwright.

Open the folder on GitHubat commit 7e39435

Compare with similar skills

Figma Typings Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Figma Typings Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Figma Typings Audit this skillawdr74100/figwright1k—~3.3kAutomated safety check: PassMIT
Zodjasonjgardner/blockbench-mcp-plugin5003 repos~1.4kAutomated safety check: PassGPL-3.0
Changelogratel-ai/ratel471—~1.6kAutomated safety check: PassMIT
Project Docs Maintainerswimmwatch/cloakbrowser-mcp164—~569Automated safety check: PassMIT
MCP Server Trello Releasedelorenj/mcp-server-trello445—~3.5kAutomated safety check: PassMIT
Phoenix Release NotesArize-ai/phoenix12k—~6.7kAutomated safety check: PassCustom licence

Similar skills

  • Zod

    jasonjgardner/blockbench-mcp-plugin

    Zod schema validation best practices for type safety, parsing, and error handling.

    500 GitHub starsUsed in 3 repos~1.4k tokens
    DevelopmentAuto-check passed
  • Changelog

    ratel-ai/ratel

    Update per-package CHANGELOG.md files for a Ratel release. An agent skill from ratel-ai/ratel.

    471 GitHub stars~1.6k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Project Docs Maintainer

    swimmwatch/cloakbrowser-mcp

    Maintain, organize, consolidate, or audit the cloakbrowser-mcp documentation set only when the user explicitly requests project documentation maintenance or an authorized public change requires it.

    164 GitHub stars~569 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • MCP Server Trello Release

    delorenj/mcp-server-trello

    Canonical build → release → tag → publish procedure for the @delorenj/mcp-server-trello repo.

    445 GitHub stars~3.5k tokensUpdated 17 days ago
    DevelopmentAuto-check passed
  • Phoenix Release Notes

    Arize-ai/phoenix

    Create Phoenix release documentation grounded in actual code changes.

    12k GitHub stars~6.7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Siyuan Plugin Pub

    yangtaihong59/siyuan-plugins-mcp-sisyphus

    Publish the SiYuan Sisyphus plugin, standalone CLI, or both.

    116 GitHub stars~3.6k tokensUpdated 3 days ago
    DevelopmentAuto-check passed

More from awdr74100/figwright

  • MCP SDK Audit

    awdr74100/figwright

    Upgrade @modelcontextprotocol/server (the MCP TypeScript SDK v2) and prove the wire contract survived.

    1k GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Figma Build

    awdr74100/figwright

    Build a Figma design from code or a description — the reverse of figma-codegen.

    1k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Figma Codegen

    awdr74100/figwright

    Generate framework-aware code from a Figma design. An agent skill from awdr74100/figwright.

    1k GitHub stars~4.3k tokensUpdated today
    Auto-check passed

Questions about Figma Typings Audit

What does Figma Typings Audit do?

Upgrade @figma/plugin-typings and absorb what the new version exposes. Figma Typings Audit is an agent skill from awdr74100/figwright. Upgrade @figma/plugin-typings and absorb what the new version exposes.

When should I use Figma Typings Audit?

Figma Typings Audit fits situations like: the user wants @figma/plugin-typings updated; asks what a new plugin-typings version would break; newly enable — including a Renovate bump PR for that package.

How do I install Figma Typings Audit in Claude Code?

Run `npx skills add awdr74100/figwright --skill figma-typings-audit -a claude-code`. Or copy the skill folder (.claude/skills/figma-typings-audit in awdr74100/figwright) into .claude/skills/figma-typings-audit in your project. Claude Code loads it when a task matches its description.

How do I install Figma Typings Audit in Codex?

Run `npx skills add awdr74100/figwright --skill figma-typings-audit -a codex`. Or copy the skill folder (.claude/skills/figma-typings-audit in awdr74100/figwright) into .agents/skills/figma-typings-audit in your project. Codex loads it when a task matches its description.

Can I use Figma Typings Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awdr74100/figwright --skill figma-typings-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/figma-typings-audit, .gemini/skills/figma-typings-audit, .github/skills/figma-typings-audit and .opencode/skills/figma-typings-audit in your project.

What does Figma Typings Audit need to run?

Going by SKILL.md and its folder, Figma Typings Audit needs the command-line tools its instructions call (pnpm, npm, npx, tsc and git). Our summary lists: Node.js.

Does Figma Typings Audit access the network?

SKILL.md contains no URLs. Its commands use npm, npx and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Figma Typings Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Figma Typings Audit use?

Figma Typings Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Figma Typings Audit use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Figma Typings Audit?

Skills that share tags, products or a category with Figma Typings Audit: Zod (jasonjgardner/blockbench-mcp-plugin, 500 stars), Changelog (ratel-ai/ratel, 471 stars), Project Docs Maintainer (swimmwatch/cloakbrowser-mcp, 164 stars) and MCP Server Trello Release (delorenj/mcp-server-trello, 445 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Figma Typings Audit?

awdr74100 (a GitHub user) maintains it in awdr74100/figwright, which has 1,011 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.

Source: awdr74100/figwright on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.