validating-design-tokens — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited validating-design-tokens (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
var(--token-*) violationsLocate design token definitions:
ls src/styles/tokens.css src/tokens/*.css styles/variables.css 2>/dev/null
ls src/styles/tokens.ts src/tokens/*.ts 2>/dev/null
ls tokens.json style-dictionary.config.* 2>/dev/nullCommon token file patterns:
--color-*, --spacing-*, --font-*tokens.colors.*, theme.spacing.*tokens.jsonFrom CSS variables:
grep -hoE 'var\(--[a-zA-Z0-9-]+' src/styles/tokens.css | sort -uParse into categories:
| Category | Pattern | Examples |
|---|---|---|
| Colors | --color-* | --color-primary, --color-text-muted |
| Spacing | --spacing-*, --space-* | --spacing-md, --space-4 |
| Typography | --font-*, --text-* | --font-size-lg, --font-weight-bold |
| Radii | --radius-*, --rounded-* | --radius-md, --rounded-lg |
| Shadows | --shadow-* | --shadow-sm, --shadow-elevated |
| Transitions | --transition-*, --duration-* | --transition-fast |
| Z-index | --z-* | --z-modal, --z-tooltip |
Hardcoded colors in CSS:
grep -rn --include="*.css" --include="*.scss" -E '#[0-9a-fA-F]{3,8}|rgb\(|rgba\(|hsl\(' src/Hardcoded colors in JSX/TSX:
grep -rn --include="*.tsx" --include="*.jsx" -E "color:\s*['\"]#|background:\s*['\"]#|borderColor:\s*['\"]#" src/Hardcoded spacing (px values):
grep -rn --include="*.css" --include="*.scss" -E ':\s*[0-9]+px' src/ | grep -v "0px\|1px"Inline styles in React:
grep -rn --include="*.tsx" --include="*.jsx" "style={{" src/Tailwind arbitrary values (if using tokens with Tailwind):
grep -rn --include="*.tsx" --include="*.jsx" -E '\[#[0-9a-fA-F]+\]|\[[0-9]+px\]' src/Severity levels:
| Severity | Description | Examples |
|---|---|---|
| Error | Hardcoded colors in component styles | color: #333333 |
| Error | Hardcoded spacing in layout | padding: 24px |
| Warning | Inline styles with raw values | style={{ margin: 10 }} |
| Warning | Magic numbers | width: 347px |
| Info | One-off values that may be intentional | Border widths, specific dimensions |
For each violation, suggest the closest token:
## Violation Report
### src/components/Card.module.css:15
**Found**: `background-color: #f5f5f5;`
**Suggestion**: `background-color: var(--color-surface);`
### src/components/Button.tsx:42
**Found**: `padding: '16px 24px'`
**Suggestion**: `padding: 'var(--spacing-md) var(--spacing-lg)'`
### src/pages/Home.module.css:8
**Found**: `color: #1a1a1a;`
**Suggestion**: `color: var(--color-text-primary);`CSS fix pattern:
/* Before */
.card {
background-color: #ffffff;
padding: 16px;
border-radius: 8px;
box-shadow: 0 2px 4px rgba(0, 0, 0, 0.1);
}
/* After */
.card {
background-color: var(--color-surface);
padding: var(--spacing-md);
border-radius: var(--radius-md);
box-shadow: var(--shadow-sm);
}React inline style fix:
// Before
<div style={{ color: '#333', marginBottom: 16 }}>
// After
<div style={{ color: 'var(--color-text)', marginBottom: 'var(--spacing-md)' }}>
// Best: Use CSS modules instead
<div className={styles.container}>Tailwind with CSS variables:
// Before (arbitrary value)
<div className="bg-[#3b82f6] p-[24px]">
// After (use theme or CSS var)
<div className="bg-primary p-6">
// Or with CSS variable in tailwind.config.jsCreate a mapping file for consistent suggestions:
// scripts/token-map.ts
export const colorMap: Record<string, string> = {
"#ffffff": "var(--color-surface)",
"#000000": "var(--color-text)",
"#3b82f6": "var(--color-primary)",
"#ef4444": "var(--color-error)",
"#22c55e": "var(--color-success)",
};
export const spacingMap: Record<string, string> = {
"4px": "var(--spacing-xs)",
"8px": "var(--spacing-sm)",
"16px": "var(--spacing-md)",
"24px": "var(--spacing-lg)",
"32px": "var(--spacing-xl)",
};
export const findClosestToken = (
value: string,
map: Record<string, string>,
): string | null => {
return map[value.toLowerCase()] ?? null;
};Custom ESLint rule (conceptual):
// .eslintrc.js
module.exports = {
rules: {
"no-hardcoded-colors": "error",
"no-hardcoded-spacing": "warn",
},
};Stylelint for CSS:
npm install -D stylelint stylelint-declaration-strict-value// .stylelintrc.js
module.exports = {
plugins: ["stylelint-declaration-strict-value"],
rules: {
"scale-unlimited/declaration-strict-value": [
["/color/", "fill", "stroke", "background", "border-color"],
{
ignoreValues: ["transparent", "inherit", "currentColor"],
},
],
},
};## Design Token Validation Report
**Scanned**: 47 files
**Violations**: 12
**Auto-fixable**: 9
### Summary by Category
| Category | Violations | Fixable |
| ---------- | ---------- | ------- |
| Colors | 7 | 6 |
| Spacing | 4 | 3 |
| Typography | 1 | 0 |
### Violations
#### Colors (7)
| File | Line | Found | Suggested Token |
| --------------- | ---- | ----------------- | ----------------- |
| Card.module.css | 15 | `#f5f5f5` | `--color-surface` |
| Button.tsx | 42 | `#3b82f6` | `--color-primary` |
| Header.css | 8 | `rgba(0,0,0,0.5)` | `--color-overlay` |
#### Spacing (4)
| File | Line | Found | Suggested Token |
| ---------- | ---- | ------ | --------------- |
| Layout.css | 23 | `24px` | `--spacing-lg` |
| Modal.tsx | 67 | `16px` | `--spacing-md` |Before completing:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.