IN

instantly-security-basics

Guidance on implementing least-privilege security for Instantly.ai API integrations using scoped keys and secret management.

Install

mkdir -p .claude/skills/instantly-security-basics && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/3065" && unzip -o skill.zip -d .claude/skills/instantly-security-basics && rm skill.zip

Installs to .claude/skills/instantly-security-basics

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Apply Instantly.ai security best practices for API keys, scopes, and
68 charsno explicit “when” trigger
Intermediate

Key capabilities

  • →Create least-privilege API keys for Instantly
  • →Store API keys using environment variables or secret managers
  • →Implement API key rotation without downtime
  • →Validate Instantly webhook requests
  • →Review Instantly audit logs
  • →Manage workspace member permissions

How it works

This skill outlines best practices for securing Instantly.ai integrations by using scoped API keys, secure secret management, API key rotation, webhook validation, and audit logging.

Inputs & outputs

You give it
Instantly API key, desired scopes, and webhook configuration
You get back
Secure Instantly integration with scoped API keys, secret management, and validated webhooks

When to use instantly-security-basics

  • →Defining least-privilege API scopes for automation
  • →Auditing workspace permissions and key access
  • →Securing webhook endpoints

About this skill

Instantly Integration Security Baseline

Overview

Produce a verified security baseline with least privilege and explicit remediation approvals. Record assumptions, evidence, approval state, and rollback ownership so another operator can reproduce the result.

Prerequisites

  • The target repository, Instantly workspace, environment, and accountable owner
  • Current security, privacy, compliance, capacity, and change-control requirements
  • An approved API v2 key only when a bounded live verification is necessary

Tool Discipline

Use Read, Glob, and Grep to inspect code, configuration, and evidence. Use WebFetch only for current first-party Instantly documentation and package metadata. Use Write or Edit only when implementation was requested and exact target files are known; never write credentials, lead data, email content, or unrestricted environment output.

Current Contract

  • Keys are bearer credentials displayed once; store them only in approved server-side secret systems.
  • Scopes can be resource/action-specific and revoked through API-key controls.
  • Webhook payloads can contain sensitive lead and message content; the public guide does not establish a signature secret.

Authentication

Use an API v2 key as Authorization: Bearer <key> against https://api.instantly.ai/api/v2. Grant only the endpoint-specific scopes needed, inject the key from an approved server-side secret manager, and never print, persist, commit, or place it in a URL. Treat key creation, rotation, revocation, member changes, workspace delegation, and production access as owner-approved actions.

Instructions

  1. Inventory secrets, scopes, members, service identities, workspace-group delegation, and webhook destinations.
  2. Remove browser exposure, query-string keys, plaintext configs, and unrestricted environment logging.
  3. Map each call to least-privilege scopes and validate denied operations.
  4. Enforce TLS, request-size bounds, schema validation, idempotency, and payload minimization at webhook receivers.
  5. Review audit logs and establish key rotation/revocation and incident ownership.
  6. Prepare changes with blast radius, approval, verification, and rollback evidence.

Approval Boundaries

Do not create, rotate, reveal, or revoke keys; invite or remove members; delegate across workspaces; connect sending accounts; create or activate campaigns; import or delete leads; change suppression or retention; register, patch, resume, or delete webhooks; alter plans or paid capacity; transmit diagnostics; or perform another production mutation without explicit approval from the accountable owner. Keep diagnosis read-only unless implementation was requested.

Output

Return the workspace-safe scope, files and contracts inspected, exact API v2 routes and required scopes, evidence collected, validation result, sensitive fields redacted, remaining risk, accountable owner, approval state, and rollback or next action.

Error Handling

ConditionResponse
401Stop and verify that the bearer key exists, is current, and was not revoked.
403Stop and compare the operation with its exact required scope; do not broaden to all:all by default.
429Coordinate the workspace-wide budget, honor endpoint overrides, and bound retries.
Schema or tenant mismatchFail closed, preserve redacted evidence, and do not retry a mutation.

Examples

Use a compact handoff that makes scope, mutation authority, and evidence reviewable.

Input:

mode=audit; secrets=references-only; webhook-signature=not-assumed

Expected handoff:

findings=prioritized; credentials=redacted; changes=awaiting-owner

Resources

When not to use it

  • →When an Instantly account with API access is not available
  • →When understanding of environment variable management is lacking
  • →When access to Instantly dashboard Settings > Integrations is not available

Prerequisites

Instantly account with API accessUnderstanding of environment variable managementAccess to Instantly dashboard Settings > Integrations

Limitations

  • →Using `all:all` scope gives unrestricted access and is for dev/test only
  • →Webhook validation requires custom headers or IP allowlisting
  • →Audit log availability depends on the Instantly plan

How it compares

This skill provides a structured approach to Instantly security, focusing on granular access control and secure credential handling, which is more reliable than basic API key usage.

Compared to similar skills

instantly-security-basics side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
instantly-security-basics (this skill)12moReviewIntermediate
reverse-engineering-tools735moNo flagsAdvanced
game-hacking-techniques424moNo flagsAdvanced
solidity-security154moNo flagsIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

More by jeremylongshore

View all by jeremylongshore →

analyzing-logs

jeremylongshore

Analyze application logs to detect performance issues, identify error patterns, and improve stability by extracting key insights.

14123

ollama-setup

jeremylongshore

Configure auto-configure Ollama when user needs local LLM deployment, free AI alternatives, or wants to eliminate hosted API costs. Trigger phrases: "install ollama", "local AI", "free LLM", "self-hosted AI", "replace OpenAI", "no API costs". Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.

1167

backtesting-trading-strategies

jeremylongshore

Backtest crypto and traditional trading strategies against historical data. Calculates performance metrics (Sharpe, Sortino, max drawdown), generates equity curves, and optimizes strategy parameters. Use when user wants to test a trading strategy, validate signals, or compare approaches. Trigger with phrases like "backtest strategy", "test trading strategy", "historical performance", "simulate trades", "optimize parameters", or "validate signals".

1071

generating-database-seed-data

jeremylongshore

Process this skill enables AI assistant to generate realistic test data and database seed scripts for development and testing environments. it uses faker libraries to create realistic data, maintains relational integrity, and allows configurable data volumes. u... Use when working with databases or data models. Trigger with phrases like 'database', 'query', or 'schema'.

1033

cursor-codebase-indexing

jeremylongshore

Execute set up and optimize Cursor codebase indexing. Triggers on "cursor index setup", "codebase indexing", "index codebase", "cursor semantic search". Use when working with cursor codebase indexing functionality. Trigger with phrases like "cursor codebase indexing", "cursor indexing", "cursor".

885

testing-mobile-apps

jeremylongshore

Execute mobile app testing on iOS and Android devices/simulators. Use when performing specialized testing. Trigger with phrases like "test mobile app", "run iOS tests", or "validate Android functionality".

810

You might also like

reverse-engineering-tools

gmh5225

Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.

73204

game-hacking-techniques

gmh5225

Guide for game hacking techniques and cheat development. Use this skill when researching memory manipulation, code injection, ESP/aimbot development, overlay rendering, or game exploitation methodologies.

42128

solidity-security

wshobson

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.

15115

1password

openclaw

Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.

2799

senior-security

davila7

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.

3191

ghidra

mitsuhiko

Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.

16105

Search skills

Search the agent skills registry