instantly-security-basics
Guidance on implementing least-privilege security for Instantly.ai API integrations using scoped keys and secret management.
Install
mkdir -p .claude/skills/instantly-security-basics && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/3065" && unzip -o skill.zip -d .claude/skills/instantly-security-basics && rm skill.zipInstalls to .claude/skills/instantly-security-basics
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Apply Instantly.ai security best practices for API keys, scopes, andKey capabilities
- →Create least-privilege API keys for Instantly
- →Store API keys using environment variables or secret managers
- →Implement API key rotation without downtime
- →Validate Instantly webhook requests
- →Review Instantly audit logs
- →Manage workspace member permissions
How it works
This skill outlines best practices for securing Instantly.ai integrations by using scoped API keys, secure secret management, API key rotation, webhook validation, and audit logging.
Inputs & outputs
When to use instantly-security-basics
- →Defining least-privilege API scopes for automation
- →Auditing workspace permissions and key access
- →Securing webhook endpoints
About this skill
Instantly Integration Security Baseline
Overview
Produce a verified security baseline with least privilege and explicit remediation approvals. Record assumptions, evidence, approval state, and rollback ownership so another operator can reproduce the result.
Prerequisites
- The target repository, Instantly workspace, environment, and accountable owner
- Current security, privacy, compliance, capacity, and change-control requirements
- An approved API v2 key only when a bounded live verification is necessary
Tool Discipline
Use Read, Glob, and Grep to inspect code, configuration, and evidence. Use WebFetch only for current first-party Instantly documentation and package metadata. Use Write or Edit only when implementation was requested and exact target files are known; never write credentials, lead data, email content, or unrestricted environment output.
Current Contract
- Keys are bearer credentials displayed once; store them only in approved server-side secret systems.
- Scopes can be resource/action-specific and revoked through API-key controls.
- Webhook payloads can contain sensitive lead and message content; the public guide does not establish a signature secret.
Authentication
Use an API v2 key as Authorization: Bearer <key> against https://api.instantly.ai/api/v2. Grant only the endpoint-specific scopes needed, inject the key from an approved server-side secret manager, and never print, persist, commit, or place it in a URL. Treat key creation, rotation, revocation, member changes, workspace delegation, and production access as owner-approved actions.
Instructions
- Inventory secrets, scopes, members, service identities, workspace-group delegation, and webhook destinations.
- Remove browser exposure, query-string keys, plaintext configs, and unrestricted environment logging.
- Map each call to least-privilege scopes and validate denied operations.
- Enforce TLS, request-size bounds, schema validation, idempotency, and payload minimization at webhook receivers.
- Review audit logs and establish key rotation/revocation and incident ownership.
- Prepare changes with blast radius, approval, verification, and rollback evidence.
Approval Boundaries
Do not create, rotate, reveal, or revoke keys; invite or remove members; delegate across workspaces; connect sending accounts; create or activate campaigns; import or delete leads; change suppression or retention; register, patch, resume, or delete webhooks; alter plans or paid capacity; transmit diagnostics; or perform another production mutation without explicit approval from the accountable owner. Keep diagnosis read-only unless implementation was requested.
Output
Return the workspace-safe scope, files and contracts inspected, exact API v2 routes and required scopes, evidence collected, validation result, sensitive fields redacted, remaining risk, accountable owner, approval state, and rollback or next action.
Error Handling
| Condition | Response |
|---|---|
401 | Stop and verify that the bearer key exists, is current, and was not revoked. |
403 | Stop and compare the operation with its exact required scope; do not broaden to all:all by default. |
429 | Coordinate the workspace-wide budget, honor endpoint overrides, and bound retries. |
| Schema or tenant mismatch | Fail closed, preserve redacted evidence, and do not retry a mutation. |
Examples
Use a compact handoff that makes scope, mutation authority, and evidence reviewable.
Input:
mode=audit; secrets=references-only; webhook-signature=not-assumed
Expected handoff:
findings=prioritized; credentials=redacted; changes=awaiting-owner
Resources
When not to use it
- →When an Instantly account with API access is not available
- →When understanding of environment variable management is lacking
- →When access to Instantly dashboard Settings > Integrations is not available
Prerequisites
Limitations
- →Using `all:all` scope gives unrestricted access and is for dev/test only
- →Webhook validation requires custom headers or IP allowlisting
- →Audit log availability depends on the Instantly plan
How it compares
This skill provides a structured approach to Instantly security, focusing on granular access control and secure credential handling, which is more reliable than basic API key usage.
Compared to similar skills
instantly-security-basics side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| instantly-security-basics (this skill) | 1 | 2mo | Review | Intermediate |
| reverse-engineering-tools | 73 | 5mo | No flags | Advanced |
| game-hacking-techniques | 42 | 4mo | No flags | Advanced |
| solidity-security | 15 | 4mo | No flags | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
reverse-engineering-tools
gmh5225
Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.
game-hacking-techniques
gmh5225
Guide for game hacking techniques and cheat development. Use this skill when researching memory manipulation, code injection, ESP/aimbot development, overlay rendering, or game exploitation methodologies.
solidity-security
wshobson
Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.
1password
openclaw
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.
senior-security
davila7
Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.
ghidra
mitsuhiko
Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.