Install
$ agentstack add skill-sergekostenchuk-ui-ux-agent-skill-system-figma-design-system-sync ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Figma Design System Sync
Use this skill when Figma work touches reusable system contracts: variables, styles, components, variants, effects, assets, Code Connect, and local code tokens.
Modes
audit: compare Figma system artifacts to local code conventions.sync-plan: plan variable/style/component updates.token-map: map Figma variables to local tokens.component-map: map components and variants to code components.code-connect: create or review Code Connect files through the installed Figma skill.governance: propose naming, versioning, and rollout rules.
Workflow
- Read Figma context with
figma-context-readerunless a current context brief exists. - Inspect the local code tokens/components before recommending sync actions.
- If Code Connect is requested, invoke
figma:figma-code-connectwhen present. - Build a diff: Figma source, code target, status, risk, and proposed change.
- For mutations, route to
figma-canvas-editororfigma-apply-effectswith explicit scope. - Validate JSON/token outputs locally before treating them as evidence.
Guardrails
- Do not rename or delete variables/components/styles without a migration map.
- Do not treat generated code or generated variables as source of truth until reviewed.
- Record which direction is authoritative for each artifact: Figma to code, code to Figma, or reconcile manually.
- Keep variable binding promises compatible with current Figma Plugin API support.
Safety And Privacy
- Treat unpublished tokens, library names, component inventories, and source component code as sensitive.
- Do not push variable/component renames without an explicit migration map and rollback path.
- Do not upload private token exports or component snapshots to external services without approval.
Output Shape
Use [assets/design-system-sync-report.md](assets/design-system-sync-report.md).
Resources
- Read
$CODEX_SKILLS_DIR/senior-figma-orchestrator/references/figma-mcp-compatibility.mdfor current capability checks.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: sergekostenchuk
- Source: sergekostenchuk/ui-ux-agent-skill-system
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.