import-tokens-figma
Warn
Audited by Snyk on Jun 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). At runtime, the workflow ingests outsider-authored free text from a user-supplied DTCG
tokens.jsonfile (public/forwarded/downloaded content) vianode scripts/parse-tokens.mjs tokens.tokens.json, which parses JSON leaf$value/$extensionsinto theTOKENSconstants that are then pasted intoscripts/apply-tokens.jsand used by theuse_figmaLLM-executed script.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata