figma-deploy-integration

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
references/google-cloud-run-design-token-api.md

No direct evidence of malicious behavior or intentional obfuscation is present. The configuration performs expected containerization, secret storage, and Cloud Run deployment. The main security risk is that the service is unauthenticated publicly, while its runtime implementation is omitted; application-level authorization and protection of the Figma token require review. The token should also be supplied through a secure CI secret mechanism with shell tracing and log exposure prevented.

Confidence: 94%Severity: 58%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:45 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Ftons-of-skills-marketplace%2Ffigma-deploy-integration%2F@9e985d460b8ae3d2ac0e6e1347ed704758ba7d8b3514b53f6dd49fa026fee236
Security Audit — socket — figma-deploy-integration