Figma Design System Builder
warpdotdev/warp
Builds or updates a design system in Figma from a codebase in ordered phases: discovery, variables and tokens, components, theming and documentation, with checkpoints.
Find hardcoded colour, spacing and type values and wrong-tier token references in consuming code.
$ npx skills add murphytrueman/design-system-ops --skill token-compliance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install murphytrueman/design-system-ops token-compliance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/murphytrueman/design-system-ops.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/token-compliance .claude/skills/token-compliance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "token-compliance" agent skill from https://github.com/murphytrueman/design-system-ops/tree/main/skills/token-compliance into .claude/skills/token-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "token-compliance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/murphytrueman/design-system-ops/tree/main/skills/token-complianceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add murphytrueman/design-system-ops --skill token-compliance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install murphytrueman/design-system-ops token-compliance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/murphytrueman/design-system-ops.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/token-compliance .agents/skills/token-compliance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "token-compliance" agent skill from https://github.com/murphytrueman/design-system-ops/tree/main/skills/token-compliance into .agents/skills/token-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "token-compliance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add murphytrueman/design-system-ops --skill token-compliance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install murphytrueman/design-system-ops token-compliance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/murphytrueman/design-system-ops.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/token-compliance .cursor/skills/token-compliance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "token-compliance" agent skill from https://github.com/murphytrueman/design-system-ops/tree/main/skills/token-compliance into .cursor/skills/token-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "token-compliance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/murphytrueman/design-system-ops.git --path skills/token-compliance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add murphytrueman/design-system-ops --skill token-compliance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install murphytrueman/design-system-ops token-compliance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/murphytrueman/design-system-ops.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/token-compliance .gemini/skills/token-compliance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "token-compliance" agent skill from https://github.com/murphytrueman/design-system-ops/tree/main/skills/token-compliance into .gemini/skills/token-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "token-compliance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install murphytrueman/design-system-ops token-complianceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add murphytrueman/design-system-ops --skill token-compliance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/murphytrueman/design-system-ops.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/token-compliance .github/skills/token-compliance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "token-compliance" agent skill from https://github.com/murphytrueman/design-system-ops/tree/main/skills/token-compliance into .github/skills/token-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "token-compliance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add murphytrueman/design-system-ops --skill token-compliance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install murphytrueman/design-system-ops token-compliance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/murphytrueman/design-system-ops.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/token-compliance .opencode/skills/token-compliance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "token-compliance" agent skill from https://github.com/murphytrueman/design-system-ops/tree/main/skills/token-compliance into .opencode/skills/token-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "token-compliance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
token-complianceFind hardcoded colour, spacing and type values and wrong-tier token references in consuming code.
Token Compliance is an agent skill from murphytrueman/design-system-ops. Find hardcoded colour, spacing and type values and wrong-tier token references in consuming code. Trigger: find hardcoded values, any hex in the code, are we using tokens correctly, token compliance. Do NOT use for token definitions — token-audit; token file format — schema-validator.
Its SKILL.md is about 5.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Frontend & Design, covering Design tokens. The repository describes itself as: Claude Code skills for the work that keeps a design system alive. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit f167898. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteGrepGlobBash(cat:*)Bash(find:*)Bash(head:*)Bash(ls:*)Bash(sort:*)Bash(tail:*)…and 5 more on the same allowed-tools line.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitrgnpxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Token Compliance loads about 5.8k tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 3,026 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from murphytrueman/design-system-ops at commit f167898, republished under its MIT licence (© murphytrueman). 3,026 words, ~5,809 tokens.
.claude/skills/token-compliance/SKILL.md (or your agent's skills folder).A skill for identifying token compliance violations in a codebase or implementation: hardcoded raw values where tokens should be used, wrong-tier token references, and inconsistent token application. Produces a violation report with file references and remediation guidance.
Confirm that every path in this skill's frontmatter references: exists relative to this SKILL.md. If any is missing, stop: the install is incomplete, usually because a flattening installer (for example npx skills install) dropped the repo-root knowledge-notes/ directory. Tell the user to reinstall by a method in 1-INSTALL.md and run verify-install.sh from the install root. Proceed without the references only if the user explicitly says to, and then say in the output that it was produced without the pack's reference material.
Token compliance problems compound quietly. A single hardcoded hex value does not break anything. Two hundred of them, distributed across a codebase by dozens of contributors over two years, mean that a brand refresh or a dark mode implementation becomes a manual find-and-replace operation through thousands of files rather than a token update.
The compliance check exists to catch violations before they accumulate, and to understand the pattern of violations when they already have. The pattern matters: if hardcoded values are concentrated in one product area or one team's contribution, the response is different than if they are evenly distributed.
If .ds-ops-config.yml exists, follow the configuration-and-recurring knowledge note (../../knowledge-notes/configuration-and-recurring.md) for loading, integration fallbacks and recurring runs. This skill reads:
severity.* — overrides for violation severity. Especially: hardcoded_color, wrong_tier_reference, tier_leakagesystem.theming — if true, elevate hardcoded colour violations to the configured severity (typically critical)system.styling — pre-selects the detection approachintegrations.github — the repo to check out and search (see below)integrations.style_dictionary — the parsed token tree, as the reference for what tokens exist and their correct tiersgates.* — when running as part of component-to-release, which violations block releaseGitHub (integrations.github.enabled: true):
integrations.github.repo, not GitHub's code search API (see the note's GitHub caution): code search drops #, so a colour search there returns nothing and reads as clean.rg -n --glob '*.{css,scss,less,ts,tsx,js,jsx,vue}' --glob '!**/tokens/**' --glob '!**/{dist,node_modules}/**' \
'#[0-9a-fA-F]{3,8}\b|rgba?\(|hsla?\(|oklch\('grep -rnE --include='*.css' --include='*.scss' --include='*.tsx' [etc.] --exclude-dir=tokens --exclude-dir=node_modules --exclude-dir=dist '<same pattern>' . Adjust the globs to where tokens actually live. Expect some false positives (CSS ID selectors such as #add or #faded) and weed them out by hand.px values in styling files as a spacing compliance signalStyle Dictionary (4 or 5) (integrations.style_dictionary.enabled: true):
Figma MCP (integrations.figma.enabled: true):
Token compliance has the most value on messy codebases — the ones with years of accumulated hardcoded values, inconsistent styling approaches, and multiple token migration attempts. For these codebases, apply the extended detection protocol:
Indicators of a messy codebase:
style= attributes in component templatesExtended detection for messy codebases:
Legacy value mapping. Before flagging violations, build a map of legacy values to current tokens. Many hardcoded values in legacy code were correct at the time they were written — they pre-date the token system. Map #0066CC to var(--color-action-primary) so remediation guidance is specific, not just "use a token."
Violation age estimation. Use git log -S'<value>' -- <file> (the commit that introduced the value) or git blame -w -C to estimate when violations were introduced. Plain git blame and file modification dates point at the last reformat or file move, not the original author — check for bulk formatting commits before trusting a date. Group violations by era:
Hotspot detection. Identify the 5–10 files with the most violations. These are the high-value remediation targets — fixing them reduces the violation count disproportionately. Present as:
Compliance hotspots (illustrative):
1. src/legacy/checkout/styles.scss — 47 hardcoded values (pre-token era)
2. src/components/Card/Card.styles.ts — 23 hardcoded values (migration era)
3. src/pages/Dashboard/index.tsx — 19 inline styles (post-token era — PRIORITY)Intentional override detection. Not every hardcoded value is a violation:
/* override */ or /* intentional */: list them separately as "Marked intentional in code", with the comment, so the team can confirm.<token>" and mark the row off-system in Notes: the value may be a one-off design requirement or a gap in the scale, and the team should decide which, not the tool.Ask for or confirm (skip questions already answered by auto-pull):
var(--token)), SCSS variables ($token), Tailwind utility classes, CSS-in-JS theme objects, or a mixIf no code is in reach (no path, no local checkout, no pasted files), stop and ask for one; a compliance check on described code produces guesses. The design system's own component code counts as consuming code: when the target is the system repo, say so under Scope, because the token source files are excluded and the components are what's being checked.
Styling approach matters for how violations are detected:
var(--color-action-primary). Hardcoded values are raw hex/rgb/px values outside of var().$color-action-primary or map-get($tokens, 'action-primary'). Hardcoded values are raw literals not using $ variables.bg-primary, text-color-content-default, gap-4). These are NOT hardcoded values — they are token references expressed as utility classes. Hardcoded values in Tailwind are arbitrary value brackets: h-[12px], bg-[#ff0000], p-[7px]. Flag arbitrary values as violations; do not flag standard utility classes that resolve to configured tokens.theme.colors.action.primary or tokens.spacing[4]. Hardcoded values are raw literals in style objects.Framework-specific detection notes:
<style lang="scss" scoped> blocks. Look for raw px values where $token variables or var(--token) should be used. Vue's scoped styles may also contain token references via v-bind() for dynamic CSS — these are valid token usage if bound to a token-backed prop.style="" attributes in templates (e.g. style="background-color: {{ item.color }}"), hardcoded hex values in SVG fill/stroke attributes, and raw pixel values in HTML dimension attributes. Twig components typically reference tokens via BEM utility classes — audit the SCSS that backs those classes, not just the template.theme.spacing(4) are valid token usage — find the codebase's helpers first so they aren't flagged. Template-literal CSS (css\padding: 16px``) is where raw values hide from object-syntax searches; search inside the backticks too.padding: 16, fontSize: 14) in StyleSheet.create or inline style. A numeric literal there is the hardcoded form; token references look like tokens.spacing.md or a theme hook.Excluded from all checks: token source files, generated CSS (build output), SVG assets, and stories/test fixtures. Say in the Scope block which paths were excluded.
Base severity (before the context adjustments in Step 3; severity.* config keys override):
Every violation's Location is a file and line. A finding without one is not logged.
Exempt values, everywhere: transparent, currentColor, inherit, none, and CSS-wide keywords (initial, unset, revert). These are never violations.
Find and flag all colour values that are not token references:
#0066CC, #FFF)rgb(0, 102, 204), rgba(0,0,0,0.5))red, white) — the exempt keywords above exceptedFor each finding: file reference or context, the raw value found, and the token it should reference.
If the assessment is conducted against a design file rather than code: look for any colour styles applied as raw values rather than library styles.
Find and flag spacing values that are not token references:
padding: 16px, gap: 8px)1rem when there is a spacing token for 16px/1rem)Note: not all pixel values are compliance violations. Border widths, minimum touch targets, and other fixed dimensions may be intentionally hardcoded. Where intent is ambiguous, log it as ⚪ Low and say why.
Find and flag typography values that are not token references:
font-size: 14px)font-weight: 700)line-height: 1.5)font-family: 'Inter', sans-serif)Find and flag component-level code that references primitive tokens directly rather than routing through semantic tokens:
Violation example: background-color: var(--color-blue-500) in a button implementation
Should be: background-color: var(--color-action-primary) → var(--color-blue-500)
This is the subtlest compliance violation and the most architecturally damaging. It appears correct on the surface — the right colour is being used — but it breaks the semantic contract and means a semantic change (e.g. changing what "action primary" means) does not propagate to the component.
For each finding: the token being referenced, the semantic token that should be used instead, and the context.
A component token that is defined against a primitive in the token files (card.border: {color.gray.200}) is a definition problem, and token-audit's tier-leakage check owns it. Log a wrong-tier reference here only where it appears in consuming code (var(--color-gray-200) in a component stylesheet). If you notice the definition problem on the way, name it once under Scope as handed to token-audit; don't give it a TC- id.
Find and flag cases where the same visual property is implemented differently across components or contexts:
color.action.primary in some places, color.brand.500 in others, for the same role)These violations are often invisible in a per-component review but surface clearly when components are compared.
Open with a headline sentence that tells the reader the overall state and where to focus.
Date: [date] Scope: [what was assessed] Assessment method: [codebase / design file / Storybook / described properties]
Overall compliance picture. What is the most significant finding? Is the violation pattern concentrated or distributed?
| Check | Violations found | 🔴 Critical | 🟠 High | 🟡 Medium | ⚪ Low |
|---|---|---|---|---|---|
| Hardcoded colour values | |||||
| Hardcoded spacing values | |||||
| Hardcoded typography values | |||||
| Wrong-tier token references | |||||
| Inconsistent token application | |||||
| Total |
Group by check type. For each violation:
| ID | Check | Severity | Location | Raw value / incorrect reference | Correct token | Notes |
|---|---|---|---|---|---|---|
| TC-01 | Colour | 🔴 Critical / 🟠 High / 🟡 Medium / ⚪ Low | [file path or context] | #0066CC | var(--color-action-primary) |
Each value appears once. Off-system values (no matching token) stay in this table with their severity; put "none — nearest: <token>" in the Correct token column and "off-system" in Notes. Don't repeat them in a separate list.
Excluded as structural: one line listing the values left out and why — e.g. max-width: 960px (layout container), border: 1px solid (divider), test-wrapper padding. Don't log these as violations.
Not all violations carry equal weight. Adjust severity based on component importance. This is the feature that distinguishes a compliance check from a simple grep — without context-aware severity, every violation looks the same.
Elevated severity (upgrade one level):
.ai/index/ if codebase-index has run; otherwise skip this adjustment and say so)Standard severity:
Reduced severity (downgrade one level):
max-width: 1200px for a container, height: 1px for a divider) — not violations; list them on the "Excluded as structural" lineApply the adjustment after the initial severity assignment. Note the adjustment and reason in the violation log — "Severity upgraded from Medium to High: component is on the checkout critical path."
Step back from individual violations and describe the pattern:
Pattern analysis turns a violation log into actionable intelligence. "Hardcoded spacing violations are concentrated in the legacy product area — likely pre-dates the token system" leads to a different response than "hardcoded spacing violations are evenly distributed and increasing — the token system is not being adopted."
Immediate: Wrong-tier token references and any hardcoded values that would break under theming or brand change. These have architectural impact.
Planned: Consistent hardcoded values that correspond clearly to existing tokens. These can be resolved in a systematic pass.
Review: Ambiguous values (raw percentages, context-dependent px values, intentional overrides). These need human judgment before remediation.
Recommend the most efficient approach for the volume and pattern of violations found:
stylelint-declaration-strict-value on the token-backed properties with the token pattern as ignoreValues; for Tailwind, eslint-plugin-tailwindcss no-arbitrary-value; for React Native, a custom ESLint rule on numeric style literals. governance-encoder writes the configScope
If any of these values are deliberate (a one-off the design called for, or a legacy area you've accepted), tell me and I'll exclude them in future runs.
Token definitions are out of scope for this skill: for DTCG format and alias integrity use schema-validator; for tier structure and cross-system consistency use token-audit.
© murphytrueman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/token-compliance of murphytrueman/design-system-ops.
Open the folder on GitHubat commit f167898
Token Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Token Compliance this skillmurphytrueman/design-system-ops | 206 | — | ~5.8k | Automated safety check: Pass | MIT | |
| Figma Design System Builderwarpdotdev/warp | 65k | 2 repos | ~4.4k | Automated safety check: Pass | AGPL-3.0 | |
| Figma use_figma Plugin API Ruleswarpdotdev/warp | 65k | 4 repos | ~4.4k | Automated safety check: Pass | AGPL-3.0 | |
| MCP Developmentcoollabsio/coolify | 63k | 1 repos | ~949 | Automated safety check: Pass | MIT | |
| Design SystemOhh-889/skyroc | 795 | 11 repos | ~1.7k | Automated safety check: Pass | MIT | |
| Design Dnazanwei/design-dna | 1.9k | 1 repos | ~2.1k | Automated safety check: Pass | MIT |
warpdotdev/warp
Builds or updates a design system in Figma from a codebase in ordered phases: discovery, variables and tokens, components, theming and documentation, with checkpoints.
warpdotdev/warp
Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.
coollabsio/coolify
A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.
Ohh-889/skyroc
Token architecture, component specifications, and slide generation.
zanwei/design-dna
Extract, define, and apply design DNA across three dimensions: design system (tokens), design style (qualitative feel), and visual effects (Canvas, WebGL, 3D, particles, shaders, scroll effects…
warpdotdev/warp
Turns a Figma frame or component into production code that matches the design, using the Figma MCP server and the project's own design system.
murphytrueman/design-system-ops
Write the AGENTS.md that tells coding agents how to use this design system: where things live, sourced rules, how to check work, what not to do; Claude, Cursor or Copilot pointers on request.
murphytrueman/design-system-ops
Write a six-section prose description (purpose, props, anti-patterns, composition, accessibility, examples) for a Figma component's description field so LLMs read it via MCP.
murphytrueman/design-system-ops
Write release notes, a migration guide and a team announcement for a design system change that is already decided, scaled to its impact.
murphytrueman/design-system-ops
Generate machine-readable index files in .ai/index/ (component inventory, uses/usedBy graph, stats) for AI agents.
murphytrueman/design-system-ops
Generate tested jscodeshift/postcss codemods for design system migrations: token renames, prop renames or removals, import paths, component swaps.
murphytrueman/design-system-ops
Audit prop APIs across a component library: naming consistency, boolean/default patterns, type coverage, exported types, breaking changes between versions.
Categories
Find hardcoded colour, spacing and type values and wrong-tier token references in consuming code. Token Compliance is an agent skill from murphytrueman/design-system-ops. Find hardcoded colour, spacing and type values and wrong-tier token references in consuming code.
Token Compliance fits situations like: token definitions — token-audit; token file format — schema-validator.
Run `npx skills add murphytrueman/design-system-ops --skill token-compliance -a claude-code`. Or copy the skill folder (skills/token-compliance in murphytrueman/design-system-ops) into .claude/skills/token-compliance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add murphytrueman/design-system-ops --skill token-compliance -a codex`. Or copy the skill folder (skills/token-compliance in murphytrueman/design-system-ops) into .agents/skills/token-compliance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add murphytrueman/design-system-ops --skill token-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/token-compliance, .gemini/skills/token-compliance, .github/skills/token-compliance and .opencode/skills/token-compliance in your project.
Going by SKILL.md and its folder, Token Compliance needs the command-line tools its instructions call (git, rg and npx). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Write, Grep, Glob, Bash(cat:*), Bash(find:*), Bash(head:*), Bash(ls:*), Bash(sort:*), Bash(tail:*), Bash(wc:*), Bash(grep:*), Bash(rg:*), Bash(git log:*), Bash(git blame:*).
SKILL.md contains no URLs. Its commands use git and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Token Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.8k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Token Compliance: Figma Design System Builder (warpdotdev/warp, 65k stars), Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars), MCP Development (coollabsio/coolify, 63k stars) and Design System (Ohh-889/skyroc, 795 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
murphytrueman (a GitHub user) maintains it in murphytrueman/design-system-ops, which has 206 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on September 24, 2026.
Source: murphytrueman/design-system-ops on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.