{"name":"io.github.tathagat22/plumb-mcp","slug":"tathagat22-plumb-mcp","title":null,"description":"Two-way Figma MCP: extract + verify design-to-code, or generate on-brand Figma pages from a prompt.","url":"https://mcp.market/server/tathagat22-plumb-mcp","rating":null,"grade":"C","score":65,"certified":false,"status":"active","category":"scraping","tags":["scraping","ai","media"],"presence":{"score":36,"stars":83,"forks":8,"downloads_week":null,"last_push_at":"2026-09-17T08:28:38.000Z","license":"MIT"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/tathagat22/plumb-mcp","website":"https://tathagat22.github.io/plumb-mcp/","version":"0.13.2","remotes":[],"packages":[{"registryType":"npm","identifier":"plumb-mcp","version":"0.13.2","transport":{"type":"stdio"},"environmentVariables":[{"description":"Figma personal access token (read-only). Only needed for the REST path — not required when the Plumb plugin is paired in Figma desktop. Create one at figma.com → Settings → Security → Personal access tokens.","format":"string","isSecret":true,"name":"FIGMA_TOKEN"},{"description":"Optional label shown in the Plumb Figma plugin when multiple plumb-mcp servers are paired with the same plugin (multi-agent connect). Defaults to the basename of the current working directory.","format":"string","name":"PLUMB_SESSION_NAME"}]}],"tools":[{"name":"plumb_assets","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_brand","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_components","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_describe","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_design","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_fig_node","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_fig_outline","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_fit","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_node","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_outline","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_query","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_review","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_screenshot","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_search","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_selection","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_source","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_status","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_studio","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_studio_kit","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_studio_page","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_studio_start","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_tokens","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"plumb_verify","description":"","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":65,"grade":"C","scanned_at":"2026-09-26T11:37:20.001Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-26T11:37:20.112Z","components":{"code":{"score":13,"max":25,"notes":["7 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 9 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[{"id":"exec.shell-concat","severity":"high","component":"code","title":"Shell command built from a string (injection risk)","evidence":"dist/index.js: …t-edge\"]) { try { const out = execSync(`${which} ${cmd}`, { stdio: [\"ignore\", \"pipe\", \"igno…"}],"inputs":{"packages":[{"registryType":"npm","identifier":"plumb-mcp","version":"0.13.2","found":true,"license":"MIT","hasInstallScripts":false,"dependencyCount":4,"publishedAt":"2026-07-03T22:32:45.434Z","repositoryUrl":"git+https://github.com/tathagat22/plumb-mcp.git"}],"repo":{"found":true,"owner":"tathagat22","repo":"plumb-mcp","archived":false,"pushedAt":"2026-09-17T08:28:38Z","stars":83,"forks":8,"openIssues":20,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/56931425?v=4","ownerCreatedAt":"2019-10-23T16:30:55Z","license":"MIT"},"icon":{"url":"https://avatars.githubusercontent.com/u/56931425?v=4&s=128","source":"github"},"presence":{"stars":83,"forks":8,"downloadsWeek":null,"license":"MIT","lastPushAt":"2026-09-17T08:28:38.000Z","score":36}}}},"grade_history":[],"reviews":[]}