Agent skill

Anima Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Audit and harden Anima and Figma tokens for design-to-code pipelines.

MITAuto-check: notesFrontend & Design

Install Anima Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill anima-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace anima-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/anima-security-basics .claude/skills/anima-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
anima-security-basics
GitHub stars
2.8k
Token cost
~1.6k tokens
SKILL.md length
498 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Audit and harden Anima and Figma tokens for design-to-code pipelines.

  • Works in 3 steps: Figma Token Scope Restriction → Server-Side Only Enforcement → Secret Manager Integration
  • Protecting API credentials
  • SKILL.md covers Overview, Prerequisites, Security Checklist and Instructions, plus 5 more sections
  • Calls node; needs ANIMA_TOKEN and FIGMA_TOKEN

What it does

Anima Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Audit and harden Anima and Figma tokens for design-to-code pipelines. Use when protecting API credentials, restricting Figma access scope, or hardening CI/CD design automation pipelines. Trigger with: "anima security", "anima token safety", "figma token security".

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Requires Node.js 20+, approved Anima API access, current Anima SDK documentation, and authorized Figma or website source access

It sits in Frontend & Design, covering Design to code and CI/CD. It works with Figma. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Protecting API credentials
  • Restricting Figma access scope
  • Hardening CI/CD design automation pipelines
  • With: anima security

Example prompts

  • “anima security”
  • “anima token safety”
  • “figma token security”
  • “/anima-security-basics”

Requirements

  • Node.js
  • A credential in ANIMA_TOKEN
  • A credential in FIGMA_TOKEN
  • Compatibility (from SKILL.md): Requires Node.js 20+, approved Anima API access, current Anima SDK documentation, and authorized Figma or website source access
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Figma Token Scope Restriction
  2. Server-Side Only Enforcement
  3. Secret Manager Integration

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • figma.com
    • cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ANIMA_TOKEN
    • FIGMA_TOKEN
    • FIGMA_FILE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Node.js 20+, approved Anima API access, current Anima SDK documentation, and authorized Figma or website source access

    From compatibility in the SKILL.md frontmatter.

Context cost

Anima Security Basics loads about 1.6k tokens when it runs, and up to ~1.7k if it reads all its reference files. Until then it costs about 72 tokens; SKILL.md has 498 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:49
    nima token stored in secret manager (not .env in prod)
  • NoteMentions a .env fileSKILL.md:52
    - [ ] `.env` files gitignored and chmod 600

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 498 words, ~1,550 tokens.

Download SKILL.mdSave it as .claude/skills/anima-security-basics/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
anima-security-basics
description
Audit and harden Anima and Figma tokens for design-to-code pipelines. Use when protecting API credentials, restricting Figma access scope, or hardening CI/CD design automation pipelines. Trigger with: "anima security", "anima token safety", "figma token security".
allowed-tools
Read, Write, Edit, Grep
compatibility
Requires Node.js 20+, approved Anima API access, current Anima SDK documentation, and authorized Figma or website source access
version
2.0.0
argument-hint
[pipeline-or-environment]
model
inherit
effort
high
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, design, figma, anima, security

Anima Security Basics

Overview

This workflow protects the Anima and Figma credentials used by a design-to-code pipeline while keeping generated output reviewable. It applies least privilege to the design source, keeps tokens on the server, and makes secret exposure or unexpected file access a fail-closed condition.

Prerequisites

  • A managed secret store and separate development, staging, and production bindings for ANIMA_TOKEN and FIGMA_TOKEN.
  • An allowlist of Figma file keys and component node IDs, with an owner for each design source and a documented rotation/revocation contact.
  • A non-production fixture and a disposable staging workspace for testing token scope, generated artifacts, and rollback behavior.
  • Repository secret scanning and a deterministic generated-code directory; never use real customer or personal design data as the test fixture.

Security Checklist

  • Anima token stored in secret manager (not .env in prod)
  • Figma token uses only the endpoint-required granular read scopes
  • SDK runs server-side only (never ship tokens to browser)
  • .env files gitignored and chmod 600
  • CI secrets stored in GitHub Secrets, not workflow files
  • Generated code reviewed before committing (no embedded tokens)

Instructions

Step 1: Figma Token Scope Restriction
bash
# When creating a Figma Personal Access Token:
# - Start with file_content:read for file/node content.
# - Add file_metadata:read, file_versions:read, or library read scopes only
#   when the selected endpoint requires them.
# - Do not use the deprecated broad files:read scope for new integrations.
# - Set an organization-approved expiration date.
# - Create separate tokens for dev vs CI environments
Step 2: Server-Side Only Enforcement
typescript
// src/anima/safety.ts
// Anima SDK is designed for server-side use only

function validateEnvironment(): void {
  if (typeof window !== 'undefined') {
    throw new Error('Anima SDK must run server-side only — never import in browser code');
  }
  if (!process.env.ANIMA_TOKEN) throw new Error('ANIMA_TOKEN not set');
  if (!process.env.FIGMA_TOKEN) throw new Error('FIGMA_TOKEN not set');
}

// Call this at startup
validateEnvironment();

Error Handling

FailureRequired response
Secret manager is unavailable or a required token is emptyAbort before any Figma or Anima request; emit only a redacted reason and retry through the deployment system.
A browser bundle imports the SDK or contains a tokenFail the build, remove the artifact, and rotate any credential that may have been exposed.
Figma returns an authorization or scope errorStop the run and review the file/node allowlist; do not broaden scopes automatically.
A token is expired, over-scoped, or present in logs/artifactsRevoke and replace it through the managed store, then rerun the leak scan before enabling the pipeline.
Generated code contains credentials or unapproved source contentQuarantine the output and block the merge; retain only a sanitized finding and artifact digest.

All failures should preserve the previous known-good generated revision. Do not print token values, design content, personal identifiers, or full request payloads while diagnosing a failure.

Show full SKILL.md (159 more words)Show less
Step 3: Secret Manager Integration
typescript
// src/anima/secrets.ts
async function loadAnimaSecrets(): Promise<{ animaToken: string; figmaToken: string }> {
  const { SecretManagerServiceClient } = await import('@google-cloud/secret-manager');
  const client = new SecretManagerServiceClient();

  const [animaVersion] = await client.accessSecretVersion({
    name: `projects/${process.env.GCP_PROJECT}/secrets/anima-token/versions/latest`,
  });
  const [figmaVersion] = await client.accessSecretVersion({
    name: `projects/${process.env.GCP_PROJECT}/secrets/figma-token/versions/latest`,
  });

  return {
    animaToken: animaVersion.payload?.data?.toString() || '',
    figmaToken: figmaVersion.payload?.data?.toString() || '',
  };
}

Tool Discipline

Use Read and Grep to inspect the existing integration and generated diff before changing anything. Use Write or Edit only inside the approved generated-code, test, or configuration paths. Use the declared Bash commands only for the explicit install, validation, or diagnostic steps in this workflow; never print tokens, source designs, generated source, or private website captures.

Output

  • Figma token with minimal scope (read-only)
  • Server-side enforcement preventing browser usage
  • Secrets loaded from cloud secret manager

Examples

Run a staging preflight with an allowlisted synthetic file and verify that the process can read the managed bindings without revealing their values:

bash
export FIGMA_FILE_KEY="synthetic-staging-file"
node scripts/anima-preflight.mjs \
  --file-key "$FIGMA_FILE_KEY" \
  --node-id "1:2" \
  --check-token-scope \
  --assert-server-only \
  --redact-output

The preflight should fail closed if either secret is absent, the file or node is not allowlisted, or a generated artifact contains a token. Record only the environment, source identifier, scope result, artifact digest, and cleanup result in the receipt; never record the credentials or design contents.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/anima-security-basics of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Anima Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Anima Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Anima Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: NotesMIT
Figma use_figma Plugin API Ruleswarpdotdev/warp65k4 repos~4.4kAutomated safety check: PassAGPL-3.0
Figma Design to Codewarpdotdev/warp65k4 repos~2.9kAutomated safety check: PassAGPL-3.0
Figma Design System Rules Generatorwarpdotdev/warp65k3 repos~4.6kAutomated safety check: PassAGPL-3.0
Figma Code Connect Componentswarpdotdev/warp65k2 repos~4.2kAutomated safety check: PassAGPL-3.0
Design To CodeMigoXLab/coderio1142 repos~1.2kAutomated safety check: PassApache-2.0

Similar skills

  • Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.

    65k GitHub starsUsed in 4 repos~4.4k tokens
    Frontend & DesignAuto-check passed
  • Figma Design to Code

    warpdotdev/warp

    Turns a Figma frame or component into production code that matches the design, using the Figma MCP server and the project's own design system.

    65k GitHub starsUsed in 4 repos~2.9k tokens
    Frontend & DesignAuto-check passed
  • Creates project-specific design system rules from your codebase so coding agents implement Figma designs with your components, naming and tokens.

    65k GitHub starsUsed in 3 repos~4.6k tokens
    Frontend & DesignAuto-check passed
  • Maps published Figma components to their code implementations with Code Connect, using the Figma MCP suggestion and mapping tools.

    65k GitHub starsUsed in 2 repos~4.2k tokens
    Frontend & DesignAuto-check passed
  • Design To Code

    MigoXLab/coderio

    Pixel-perfect Figma to React conversion using coderio. An agent skill from MigoXLab/coderio.

    114 GitHub starsUsed in 2 repos~1.2k tokens
    Frontend & DesignAuto-check passed
  • Figma Screen Generator

    warpdotdev/warp

    Builds or updates full Figma screens from code or a description by reusing the file's published design system components, variables and styles.

    65k GitHub starsUsed in 2 repos~5k tokens
    Frontend & DesignAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Anima Security Basics

What does Anima Security Basics do?

Audit and harden Anima and Figma tokens for design-to-code pipelines. Anima Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Audit and harden Anima and Figma tokens for design-to-code pipelines.

When should I use Anima Security Basics?

Anima Security Basics fits situations like: protecting API credentials; restricting Figma access scope; hardening CI/CD design automation pipelines; with: anima security.

How do I install Anima Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill anima-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/anima-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/anima-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Anima Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill anima-security-basics -a codex`. Or copy the skill folder (skills/.curated/anima-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/anima-security-basics in your project. Codex loads it when a task matches its description.

Can I use Anima Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill anima-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/anima-security-basics, .gemini/skills/anima-security-basics, .github/skills/anima-security-basics and .opencode/skills/anima-security-basics in your project.

What does Anima Security Basics need to run?

Going by SKILL.md and its folder, Anima Security Basics needs the command-line tools its instructions call (node) and credentials named ANIMA_TOKEN, FIGMA_TOKEN and FIGMA_FILE_KEY. Our summary lists: Node.js; A credential in ANIMA_TOKEN; A credential in FIGMA_TOKEN. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep. Compatibility (from SKILL.md): Requires Node.js 20+, approved Anima API access, current Anima SDK documentation, and authorized Figma or website source access.

Does Anima Security Basics access the network?

SKILL.md names 2 domains. As links in the text: figma.com and cloud.google.com. This is read from the text; nothing was executed.

Is Anima Security Basics safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Anima Security Basics use?

Anima Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Anima Security Basics use?

About 1.6k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 188 tokens, read only when the agent opens those files.

What are the alternatives to Anima Security Basics?

Skills that share tags, products or a category with Anima Security Basics: Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars), Figma Design to Code (warpdotdev/warp, 65k stars), Figma Design System Rules Generator (warpdotdev/warp, 65k stars) and Figma Code Connect Components (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Anima Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.