MCP SDK Audit
awdr74100/figwright
Upgrade @modelcontextprotocol/server (the MCP TypeScript SDK v2) and prove the wire contract survived.
Pre-ship gate for a Figma handoff. An agent skill from hashgraph-online/awesome-codex-plugins.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill figma-handoff-gate -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins figma-handoff-gate --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate .claude/skills/figma-handoff-gate && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "figma-handoff-gate" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate into .claude/skills/figma-handoff-gate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "figma-handoff-gate", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill figma-handoff-gate -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins figma-handoff-gate --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate .agents/skills/figma-handoff-gate && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "figma-handoff-gate" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate into .agents/skills/figma-handoff-gate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "figma-handoff-gate", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill figma-handoff-gate -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins figma-handoff-gate --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate .cursor/skills/figma-handoff-gate && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "figma-handoff-gate" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate into .cursor/skills/figma-handoff-gate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "figma-handoff-gate", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/hashgraph-online/awesome-codex-plugins.git --path plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill figma-handoff-gate -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins figma-handoff-gate --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate .gemini/skills/figma-handoff-gate && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "figma-handoff-gate" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate into .gemini/skills/figma-handoff-gate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "figma-handoff-gate", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install hashgraph-online/awesome-codex-plugins figma-handoff-gateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add hashgraph-online/awesome-codex-plugins --skill figma-handoff-gate -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate .github/skills/figma-handoff-gate && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "figma-handoff-gate" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate into .github/skills/figma-handoff-gate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "figma-handoff-gate", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill figma-handoff-gate -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins figma-handoff-gate --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate .opencode/skills/figma-handoff-gate && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "figma-handoff-gate" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate into .opencode/skills/figma-handoff-gate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "figma-handoff-gate", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
figma-handoff-gatePre-ship gate for a Figma handoff. An agent skill from hashgraph-online/awesome-codex-plugins.
Figma Handoff Gate is an agent skill from hashgraph-online/awesome-codex-plugins. Pre-ship gate for a Figma handoff. Runs 17 checks before a section is declared ready for developers: action completeness (every drawn action has a designed outcome, and inverse pairs such as add and remove both exist), annotation layout and contrast, dense spec cards with no AI stuffing, a hand-crafted surface with no trace of the process, and proof at the right scale. Run figma-slop-check first. Use when the user says "ready for handoff", "dev-tag", "release section", "spec card", "run the handoff gate", or in…
Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Read-only until a fix is approved. Detector snippets are Plugin API JavaScript written for figmaexecute (figma-console-mcp, Desktop Bridge plugin in Figma…
It sits in Agent Workflows. It works with Figma. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9e7b281. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Read-only until a fix is approved. Detector snippets are Plugin API JavaScript written for figma_execute (figma-console-mcp, Desktop Bridge plugin in Figma Desktop). The official Figma MCP server's use_figma also runs Plugin API JavaScript, but this gate was not validated there. Reads the figma-canon skill; approved fixes go through figma-preflight.
From compatibility in the SKILL.md frontmatter.
Figma Handoff Gate loads about 5k tokens when it runs. Until then it costs about 142 tokens; SKILL.md has 2,436 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from hashgraph-online/awesome-codex-plugins at commit 9e7b281, republished under its MIT licence (© hashgraph-online). 2,436 words, ~5,049 tokens.
.claude/skills/figma-handoff-gate/SKILL.md (or your agent's skills folder).Pre-ship gate for handoff sections. It catches handoff-specific bugs that a slop and precision pass misses: orphan actions, weak annotations, inflated screen counts, process residue on the canvas, proof taken at the wrong scale.
Run figma-slop-check first. This gate assumes the screens already passed it.
The detector snippets below are Plugin API JavaScript. Run them through figma_execute (figma-console MCP server, Desktop Bridge plugin running in Figma Desktop). The gate reports. It changes nothing on the canvas until the user approves a fix (see "Apply-fix commands").
figma-slop-check passes on the same section.The canon is figma-canon/references/handoff-format.md. Its "Terms" section (figma-canon/references/handoff-format.md#terms) defines spec card, caption and note card, the three surfaces these checks name.
Required checks (all must pass). Report a broken requirement as [BLOCKER]. Report an item that a check only asks you to flag (for example a gap over 120px in check 1) as [WARN]. Any finding of either level puts the result in the FAIL template, which lists both as issues before ship.
SCREEN_TO_ANNOTATION_GAP = 80px (screen right edge to annotation column left edge)CLUSTER_TO_CLUSTER_GAP_H = 160px (cluster to next cluster)ROW_GAP_V = 200px (cluster row to next cluster row)SECTION_TITLE_CLEARANCE = 48pxfigma-canon/references/handoff-format.md#spacing-canon for the full tablefigma-canon/references/handoff-format.md for the diagramWhy: / Edge: prefixes. That accent is part of the note card spec, not amber slop.deliverable + valueTICKET-123), internal tool names ("the v2 validator"), registry or rule codes, and the like@user_NNN placeholders (use realistic names or strip)figma-canon/references/ai-slop-signatures.mdfigma-canon/references/handoff-format.md#state-variants-live-in-component-sets, and your project's own build skill or workflow, if anyfigma-canon/references/handoff-format.md#4-lens-pre-ship-critique-mandatory for the questions of each lens@user_123: replace them with realistic names in the file's language.figma-canon/references/handoff-format.md#project-locale-and-sample-namesfigma-canon/references/handoff-format.md#reports--comms and "Self-corrections in reports" in figma-canon/references/ai-slop-signatures.md' and "findAll(section, n => n.type === "TEXT" && (n.characters.includes("\u2014") || /[\u2019\u2018\u201C\u201D]/.test(n.characters)))findAll(section, fn) above is shorthand. In the Plugin API it is section.findAll(fn).const re = /[\u2014\u2018\u2019\u201C\u201D]/;
const section = await figma.getNodeByIdAsync("123:456"); // the section's node id
const nodes = [section, ...section.findAll(() => true)];
return nodes
.filter(n => re.test(n.name) || ("description" in n && re.test(n.description || "")))
.map(n => ({ id: n.id, name: n.name }));figma-canon/references/state-coverage.md#16181D, stroke #2A2E37, title #FFFFFF, body #C4C8D0Why: / Edge: prefixes (for example a green and an amber). With no project accent, use #E5484D (configurable) for the label. With no second accent, reuse the label accent for the prefixes, as figma-canon/references/handoff-format.md specifies.HandoffNote component instance (NOT raw frames). No prebuilt component ships with these skills: if the file has no annotation component, build one once from the spec in figma-canon/references/handoff-format.md, then reuse instancesWhen [trigger], [outcome]. (a human sentence: subject + verb + condition)figma-canon/references/handoff-format.md#annotation-pattern-cross-project-canon-2026-05-25The single most-repeated miss (field note, 2026-05: a developer saw an "add" action drawn and had to ask how removing would work). The developer builds exactly what is drawn: every visual action needs its outcome drawn, or the developer has to guess.
findAll every interactive element: buttons, CTAs, icon buttons, info/help (i) icons, toggles, radio/checkbox rows, list rows (tappable), chips, links, kebab/overflow menus, swipe affordances, FABs. List them.screen.findAll(n => n.reactions && n.reactions.length > 0) (reactions live on nested children, not on the screen frame root: see "Prototype reads" in figma-canon/references/plugin-api-anomalies.md). Then walk the screen for the element types above that are drawn but not wired, by layer and component names and by eye. An unwired control is exactly what this check hunts.figma-preflight ("Cross-screen flow") cross-checks the same screens for dangling CTAs and dead ends.(i) / ? / help affordance MUST open a designed info screen or sheet (not a dangling icon).This is mechanical on purpose: it removes reliance on "remembering to design the whole flow". Run it as the LAST gate check before declaring the handoff done.
Calibrated on a client handoff (field note, 2026-07). Rule: nothing in a delivered handoff may look machine-made; every surface must read as hand-crafted. In a file that a client, owner or external stakeholder will open:
figma-canon/references/plugin-api-core.md): frame.layoutGrids = frame.layoutGrids.map(g => ({ ...g, visible: false })).page.findAllWithCriteria({ types: ["TEXT"] }) and match them against a term list (ChatGPT, GPT, adversarial, fix list, sprint, QA, external review, prompt, plus the names of the AI tools, skills and pipelines your own process used), then triage the hits by hand. On a large page, raise the figma_execute timeout (default 5000 ms, maximum 30000 ms). Watch for false positives: "This is a prompt message." is the prompt slot of an iOS navigation bar, and a place name can contain "AI" as a substring ("Mumbai").The checks above measure STRUCTURE. None of them measures USE, and all of them inherit the scale of the artifact you looked at. On one delivery of an options board, figma-slop-check (both lenses), this gate and a flow-graph audit (such as the audit mode of figma-preflight) all came back green, and four real defects survived.
17a. Proof of a small element is a capture of the NODE, at scale >= 2x. The send button of a composer was an empty ellipse, with no icon, on 16 screens. It had been checked several times on a render of the whole section scaled down to 40%, where 36px becomes a colored dot. Rule: list the elements under ~48px that you created or cloned (send button, chip, badge, toggle, avatar, icon) and capture ONE of each type in isolation, at 2x or more: figma_capture_screenshot with that element's nodeId and scale set to 2 or higher. A container render does not judge a small element.
17b. An entry point is not wiring. Wiring between frames and reachability are one axis. The starting point of the prototype is another. A perfectly connected graph can open on a random screen when the stakeholder presses Present. Before writing "clickable" or "you can walk through it", run:
figma.currentPage.flowStartingPoints.map(f => f.nodeId)and confirm that the screens you are going to present are in the result. Flow starting points belong to a page, and figma.currentPage is whatever page is active, which another session or the designer can switch. Make sure the page that holds the prototype is the active one first (re-assert it from a known node, as in "findAllWithCriteria runs on figma.currentPage" in figma-canon/references/plugin-api-anomalies.md).
17c. Simulate the recipient, in writing. Before sending, answer as the recipient:
PASS figma-handoff-gate: all 17 checks clear. Handoff ship-ready.
Section: <section name>
Frames: <N>
Components used: <N>
Last verified: <timestamp>
Action -> outcome map:
<action> -> <frame name> (<node-id>)
...FAIL figma-handoff-gate: <N> issue(s) before ship:
[BLOCKER] 1. <issue> -> location <node-id> -> apply-fix: <command>
[WARN] 2. <issue> -> location <node-id> -> fix: <description>
...
Action -> outcome map:
<action> -> <frame name> (<node-id>)
<action> -> ORPHAN
...
Run apply-fix commands OR address manually, then re-invoke gate.Either result carries the action -> outcome map from check 15. Each orphan action is a [BLOCKER], never a [WARN].
For automated fixes, the gate emits explicit commands like:
figma_execute: set frame "01-home" gap to 80pxfigma_execute: rebind caption-body from FILL-in-HUG to AUTO+FILLThese are plain-language fix descriptions addressed to figma_execute, not tool syntax: figma_execute takes Plugin API JavaScript. At apply time, write that code for the approved fix.
The user approves each fix before execution. NO mass mutation. An approved fix is a write to the file, so it goes through figma-preflight like any other figma_execute write.
If frames are mutated AFTER a gate pass, re-run the gate before re-declaring done.
figma-slop-check: runs BEFORE this gate (machine-made tells and precision pass first)figma-canon: this gate reads figma-canon/references/handoff-format.md (every check) + figma-canon/references/ai-slop-signatures.md (checks 5 and 10: "Hype copy ban" and "Self-corrections in reports")figma-preflight: gates every approved apply-fix write, and its audit mode cross-checks check 15figma-slop-check. If such a workflow exists, it writes component descriptions and this gate does not. Either way, this gate validates frame layout and spec cards, and check 11 sweeps descriptions for dashes and curly quotes© hashgraph-online, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate of hashgraph-online/awesome-codex-plugins.
Open the folder on GitHubat commit 9e7b281
Figma Handoff Gate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Figma Handoff Gate this skillhashgraph-online/awesome-codex-plugins | 1.3k | — | ~5k | Automated safety check: Pass | MIT | |
| MCP SDK Auditawdr74100/figwright | 995 | — | ~4.1k | Automated safety check: Pass | MIT | |
| Integration Orchestratorrampstackco/claude-skills | 941 | — | ~5.3k | Automated safety check: Pass | MIT | |
| Product Designqf-studio/navigator | 355 | — | ~5.1k | Automated safety check: Notes | MIT | |
| MCP ServerWellApp-ai/Well | 345 | — | ~679 | Automated safety check: Pass | MIT | |
| Figma From Codebitovi/ai-enablement-prompts | 121 | — | ~7.4k | Automated safety check: Pass | MIT |
awdr74100/figwright
Upgrade @modelcontextprotocol/server (the MCP TypeScript SDK v2) and prove the wire contract survived.
rampstackco/claude-skills
Generate a phased delivery orchestration plan for creative-direction-driven work: which skills run when, what locks at which gate, how handoffs occur, and how the cadence implements in the team's…
qf-studio/navigator
Automates design review, token extraction, component mapping, and implementation planning.
WellApp-ai/Well
Guide for creating new MCP server integrations. An agent skill from WellApp-ai/Well.
bitovi/ai-enablement-prompts
Orchestrates the full code-to-Figma rebuild workflow for a web application.
bitovi/ai-enablement-prompts
Unified skill for figma-from-code Phase 3 per-component pipeline.
hashgraph-online/awesome-codex-plugins
Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.
hashgraph-online/awesome-codex-plugins
Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).
hashgraph-online/awesome-codex-plugins
A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…
hashgraph-online/awesome-codex-plugins
Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…
hashgraph-online/awesome-codex-plugins
Use CALL-E from Codex through the calle CLI. An agent skill from hashgraph-online/awesome-codex-plugins.
hashgraph-online/awesome-codex-plugins
Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.
Works with
Categories
Pre-ship gate for a Figma handoff. An agent skill from hashgraph-online/awesome-codex-plugins. Figma Handoff Gate is an agent skill from hashgraph-online/awesome-codex-plugins. Pre-ship gate for a Figma handoff.
Figma Handoff Gate fits situations like: the user says ready for handoff; release section; run the handoff gate; in Portuguese pronto pra handoff.
Run `npx skills add hashgraph-online/awesome-codex-plugins --skill figma-handoff-gate -a claude-code`. Or copy the skill folder (plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate in hashgraph-online/awesome-codex-plugins) into .claude/skills/figma-handoff-gate in your project. Claude Code loads it when a task matches its description.
Run `npx skills add hashgraph-online/awesome-codex-plugins --skill figma-handoff-gate -a codex`. Or copy the skill folder (plugins/thiagoxikota/figma-maxxing/skills/figma-handoff-gate in hashgraph-online/awesome-codex-plugins) into .agents/skills/figma-handoff-gate in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill figma-handoff-gate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/figma-handoff-gate, .gemini/skills/figma-handoff-gate, .github/skills/figma-handoff-gate and .opencode/skills/figma-handoff-gate in your project.
SKILL.md names no scripts, command-line tools or credentials: Figma Handoff Gate is instructions for the agent only. Compatibility (from SKILL.md): Read-only until a fix is approved. Detector snippets are Plugin API JavaScript written for figma_execute (figma-console-mcp, Desktop Bridge plugin in Figma Desktop). The official Figma MCP server's use_figma also runs Plugin API JavaScript, but this gate was not validated there. Reads the figma-canon skill; approved fixes go through figma-preflight..
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Figma Handoff Gate is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Figma Handoff Gate: MCP SDK Audit (awdr74100/figwright, 995 stars), Integration Orchestrator (rampstackco/claude-skills, 941 stars), Product Design (qf-studio/navigator, 355 stars) and MCP Server (WellApp-ai/Well, 345 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,255 GitHub stars. The repository holds 714 skills in this directory. The repository was last updated on October 9, 2026.
Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.