Install
$ agentstack add skill-nexu-io-open-design-figma-extract ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Figma extract
Spec §10 / §21.3.1: the figma-migration scenario starts with a Figma file URL + an OAuth token. This atom turns that pair into the authoritative on-disk record subsequent stages (token-map, generate, critique) operate on.
Inputs
| Source | Required | Notes | | --- | --- | --- | | Figma file URL or node-id | yes | Provide via the figma-oauth GenUI surface or od plugin apply --input fileUrl=… | | Figma OAuth token | yes | Routed through oauth-prompt with oauth.route='connector' and connectorId='figma'; the daemon never stores the token in SQLite |
Output
The atom writes a deterministic, JSON-shaped extract under the project cwd:
project-cwd/
├── figma/
│ ├── tree.json # canonical node tree (id / type / parent / children / box / fills / text)
│ ├── tokens.json # color + typography + spacing tokens lifted off the file
│ ├── assets/ # rasterised exports of every leaf node that the file marks for export
│ │ └── .
│ └── meta.json # { fileUrl, version, lastModified, exportedAt, atomDigest }
figma/tree.json is the canonical pivot for every downstream atom. figma/tokens.json is the input to token-map. assets/ is the input to generate's media stage.
Convergence
The atom completes when figma/tree.json exists and is non-empty. The until evaluator reads figma.tree.nodes >= 1; if the figma file is empty or the OAuth token expired, the atom emits a clear error event and the run aborts (the user fixes auth or picks a different file).
Anti-patterns the prompt fragment forbids
- Synthesising a tree from screenshots when the OAuth path failed —
always re-prompt the user; never make up node ids.
- Dropping unsupported node types silently; record them in
meta.json.unsupportedNodes[] so the human can audit gaps.
- Treating component instances as duplicates; record
componentRef
links so token-map can de-duplicate at the right boundary.
Status
Reserved id, prompt-only fragment in v1. The Figma REST + node-walk implementation lands in spec §16 Phase 6; until then plugins that declare this atom rely on their bundled MCP server (typically the community @community/figma-mcp) for the actual fetch.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: nexu-io
- Source: nexu-io/open-design
- License: Apache-2.0
- Homepage: https://open-design.ai
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.