uSpec — security grade SAFE, quality 52/100

Security audit verdict: SAFE · quality 52/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by redongreen · MCP Server · ★ 241

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is uSpec safe to install? View the security audit →

About uSpec

uSpec Generate design system documentation for your UI components — directly from your AI agent to Figma. You describe a component, an agent skill analyzes it using your Figma file as context, and renders the spec directly in your Figma file. Supports both Figma Console MCP and native Figma MCP. Works with Cursor, Claude Code, and Codex. What you can generate Get started Full documentation, installation guide, and examples at uSpec.design. License MIT — see LICENSE for details. Designed by Ian Guisard.

design-systemfigmamcpspecs

Quick Facts

Stars241
Forks32
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score52.1732627715215/100
Open Issues9
Last Updated2026-09-03
Created2026-01-23
Platformsclaude-code, codex, mcp, node
Est. Tokens~14k

Compatible Skills

These tools work well together with uSpec for enhanced workflows:

  • naksha-studio — semantic(0.32)+complementary+rare_topics+similar_pop+shared_platform (60%)
  • design-system-ops — semantic(0.44)+complementary+rare_topics+similar_pop+shared_platform (59%)
  • design-studio — semantic(0.42)+complementary+rare_topics+similar_pop+shared_platform (59%)

uSpec alternative? Top 6 similar tools

Looking for a uSpec alternative? If you're comparing uSpec with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • ux-ui-agent-skills by plugin87 · ⭐ 771

    Turn Claude into a Senior Design Architect — DTCG design tokens, 42 components, WCAG 2.2 accessibility, any-fr

  • vibe by mondaycom · ⭐ 675

    🎨 Vibe Design System - Official monday.com UI resources for application development in React.js

  • claude-talk-to-figma-mcp by arinspunk · ⭐ 645

    A Model Context Protocol (MCP) that allows Claude Desktop and other AI tools (Claude Code, Cursor, Antigravity

  • figma-mcp-bridge by gethopp · ⭐ 551

    Figma Plugin & MCP server to bypass API limits

  • naksha-studio by Adityaraj0421 · ⭐ 318

    A virtual design team for Claude Code, Cursor, Windsurf, Gemini CLI, and Copilot — 26 roles, 62 commands, 15,0

  • figma-flutter-mcp by mhmzdev · ⭐ 244

    An MCP server that provides the coding agents Figma's design token to write Flutter code.

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is uSpec?

uSpec is Generate design system documentation for your UI components, directly from your AI agent. Renders into Figma or a portable .md file. Works with Cursor, Claude Code, and Codex.. It is categorized as a MCP Server with 241 GitHub stars.

What programming language is uSpec written in?

uSpec is primarily written in TypeScript. It covers topics such as design-system, figma, mcp.

How do I install or use uSpec?

You can find installation instructions and usage details in the uSpec GitHub repository at github.com/redongreen/uSpec. The project has 241 stars and 32 forks, indicating an active community.

What license does uSpec use?

uSpec is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to uSpec?

The top alternatives to uSpec on Agent Skills Hub include ux-ui-agent-skills, vibe, claude-talk-to-figma-mcp. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools