anima-security-basics
Installation
SKILL.md
Anima Security Basics
Security Checklist
- Anima token stored in secret manager (not .env in prod)
- Figma PAT has minimum required scope (file:read only)
- SDK runs server-side only (never ship tokens to browser)
-
.envfiles gitignored and chmod 600 - CI secrets stored in GitHub Secrets, not workflow files
- Generated code reviewed before committing (no embedded tokens)