figma-multi-env-setup

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
references/environment-files.md

No executable malicious behavior is present. The fragment documents environment configuration, but it exposes credential-like Figma tokens, file keys, and a webhook passcode in the supplied text. If these are real, they should be revoked and replaced, and only blank placeholders should be published. Store all populated environment files outside version control and enforce secret scanning.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:45 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Ftons-of-skills-marketplace%2Ffigma-multi-env-setup%2F@6fd3d73af9b9c6caa8fd4c8298e88cffe02cd90ebd220cf0f2a6da6a825dfeaf
Security Audit — socket — figma-multi-env-setup