figma-ci-integration

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Security
SecurityMEDIUM
references/asset-export-on-pr.md

The workflow is not demonstrably malware, but it has a significant supply-chain and CI security risk: it runs npm installation code from a pull-request checkout and then exposes FIGMA_PAT to repository-controlled code. The export script must be reviewed separately. Use a trusted base-branch workflow or isolated validation job without secrets, pin actions to commit SHAs, restrict permissions, avoid running untrusted lifecycle scripts, and perform the privileged export and push only after trusted review.

Confidence: 97%Severity: 78%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:48 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Ftons-of-skills-marketplace%2Ffigma-ci-integration%2F@b8199f57450fe43da167d27e826278a575f11cdc58f8089338479b40dc5c0b48
Security Audit — socket — figma-ci-integration