figwright — security grade SAFE, quality 71/100

Security audit verdict: SAFE · quality 71/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by awdr74100 · MCP Server · ★ 823

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is figwright safe to install? View the security audit →

About figwright

Figwright Open-source, bidirectional Figma agent for MCP clients. A free alternative to Figma's Dev Mode MCP — your AI agent reads designs with high-fidelity grounding and writes back to the canvas. No paid Figma seat required. Where Playwright drives the browser, Figwright drives Figma. What is Figwright? Figwright connects an MCP server to a Figma plugin over a local WebSocket relay, so an AI agent — Claude Code, Cursor, or any other MCP client — can work with Figma instead of just looking at it. It works in both directions: Read — turn a Figma selection into framework-aware code, grounded on faithful, de-duplicated design context (layout, typography, variables, components). Write — author and edit the canvas directly: frames, text, auto-layout, styles, variables, components, whole screens. Everything runs on your machine and talks to Figma through a plugin, so it needs no Fi

aiclaude-codecodegencodexcursordesign-to-codefigmafigma-mcpfigma-pluginfigma-to-code

Quick Facts

Stars823
Forks47
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score71.2087153051932/100
Open Issues3
Last Updated2026-09-20
Created2026-06-18
Platformsclaude-code, cli, codex, mcp, node
Est. Tokens~17k

figwright alternative? Top 6 similar tools

Looking for a figwright alternative? If you're comparing figwright with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • figma-ui-mcp by TranHoaiHung · ⭐ 221

    AI can draw UI directly on the Figma canvas via JavaScript, and read existing designs back as structured data.

  • memorix by AVIDS2 · ⭐ 791

    Open-source cross-agent memory layer for coding agents via MCP. Compatible with Claude Code, Codex, Cursor, Wi

  • design-extract by Manavarya09 · ⭐ 4.1k

    Extract any website's complete design system with one command. DTCG tokens, semantic+primitive+composite, MCP

  • dbhub by bytebase · ⭐ 3.5k

    Token conscious database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite.

  • apple-docs-mcp by kimsungwhee · ⭐ 1.4k

    MCP server for Apple Developer Documentation - Search iOS/macOS/SwiftUI/UIKit docs, WWDC videos, Swift/Objecti

  • mysql_mcp_server by designcomputer · ⭐ 1.4k

    A Model Context Protocol (MCP) server that enables secure interaction with MySQL databases

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is figwright?

figwright is Free, two-way Figma MCP server. Turn designs into framework-aware code, and push code back to the canvas. Works with Claude Code, Cursor, Codex, and any MCP client.. It is categorized as a MCP Server with 823 GitHub stars.

What programming language is figwright written in?

figwright is primarily written in TypeScript. It covers topics such as ai, claude-code, codegen.

How do I install or use figwright?

You can find installation instructions and usage details in the figwright GitHub repository at github.com/awdr74100/figwright. The project has 823 stars and 47 forks, indicating an active community.

What license does figwright use?

figwright is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to figwright?

The top alternatives to figwright on Agent Skills Hub include figma-ui-mcp, memorix, design-extract. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools