Agent skill

Hubspot

by HybridAIOne in HybridAIOne/hybridclaw

Read HubSpot contacts, companies, and deals; update deal stages and lifecycle stages; log notes and tasks through gateway-managed bearer tokens.

MITAuto-check passedSales & Support

Install Hubspot

skills CLI
$ npx skills add HybridAIOne/hybridclaw --skill hubspot -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HybridAIOne/hybridclaw hubspot --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hubspot .claude/skills/hubspot && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hubspot
GitHub stars
159
Token cost
~3k tokens
SKILL.md length
946 words
Files
7
Skills in repo
72
Repo updated
First seen
Licence
MIT

At a glance

Read HubSpot contacts, companies, and deals; update deal stages and lifecycle stages; log notes and tasks through gateway-managed bearer tokens.

  • Works in 3 steps: Browser admin: open the active… → Browser /chat or TUI fallback → Local console fallback
  • Tasks that involve CRM management
  • SKILL.md covers Scope, Credential Rules, Default Workflow and Command Contract, plus 3 more sections
  • Runs JavaScript scripts from its folder; calls node; needs HUBSPOT_ACCESS_TOKEN and HUBSPOT_CLIENT_SECRET

What it does

Hubspot is an agent skill from HybridAIOne/hybridclaw. Read HubSpot contacts, companies, and deals; update deal stages and lifecycle stages; log notes and tasks through gateway-managed bearer tokens.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `evals/scenarios.json` and `fixtures/deal-properties.json`).

It sits in Sales & Support, covering CRM management. It works with HubSpot. The repository describes itself as: Enterprise-ready self-hosted AI assistant runtime with sandboxed execution, secure credentials, approvals, and memory. The licence is MIT.

When your agent uses it

  • Tasks that involve CRM management

Example prompts

  • “/hubspot”

Requirements

  • A credential in HUBSPOT_ACCESS_TOKEN
  • A credential in HUBSPOT_CLIENT_SECRET

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Browser admin: open the active HybridClaw admin URL ending in /admin/secrets and set
  2. Browser /chat or TUI fallback
  3. Local console fallback

What it can do on your machine

Read from SKILL.md and the folder at commit 8162701. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.hubspot.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • HUBSPOT_ACCESS_TOKEN
    • HUBSPOT_CLIENT_SECRET
    • HUBSPOT_REFRESH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hubspot loads about 3k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 946 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HybridAIOne/hybridclaw at commit 8162701, republished under its MIT licence (© HybridAIOne). 946 words, ~2,977 tokens.

Download SKILL.mdSave it as .claude/skills/hubspot/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
hubspot
description
Read HubSpot contacts, companies, and deals; update deal stages and lifecycle stages; log notes and tasks through gateway-managed bearer tokens.
user-invocable
true
requires.bins
node

HubSpot

Use this skill for HubSpot CRM work when the operator has connected HubSpot to HybridClaw with a HubSpot Service Key, legacy private app access token, or OAuth credentials.

Scope

  • read contacts, companies, and deals
  • search high-frequency CRM objects by common properties
  • inspect HubSpot CRM properties for contacts, companies, and deals
  • update a deal's dealstage
  • update contact, company, or deal lifecyclestage
  • create timeline notes associated with contacts, companies, or deals
  • create tasks associated with contacts, companies, or deals
  • plan common natural-language CRM requests before building API calls
  • build ordered natural-language workflows with lookup, property-validation, and write steps for the high-frequency CRM operations
  • validate internal HubSpot stage option values from saved property metadata
  • interpret common HubSpot authentication, authorization, stage, and rate-limit errors
  • measure cost per assistant run through normal HybridClaw UsageTotals

Credential Rules

For normal single-account HubSpot use, create a HubSpot Service Key and store it as HUBSPOT_ACCESS_TOKEN in HybridClaw encrypted runtime secrets. Service Keys are HubSpot's recommended account-level, system-to-system bearer credential for direct REST API requests when OAuth and webhooks are not needed. Never paste tokens into a prompt.

Create the Service Key in HubSpot under Development > Keys > Service keys or open https://app.hubspot.com/service-keys. Give it only the scopes needed for the requested CRM operations, copy the key, and store that value as HUBSPOT_ACCESS_TOKEN. Do not use a HubSpot Personal Access Key or Developer Key for this skill; those are for other HubSpot developer workflows and are not valid CRM REST bearer tokens for these calls. HubSpot Service Key docs: https://developers.hubspot.com/docs/apps/developer-platform/build-apps/authentication/account-service-keys.

Recommended setup order:

  1. Browser admin: open the active HybridClaw admin URL ending in /admin/secrets and set HUBSPOT_ACCESS_TOKEN.
  2. Browser /chat or TUI fallback: /secret set HUBSPOT_ACCESS_TOKEN <token>.
  3. Local console fallback:
bash
hybridclaw secret set HUBSPOT_ACCESS_TOKEN

Equivalent setup when passing the Service Key explicitly:

bash
hybridclaw auth login hubspot \
  --access-token "<hubspot-service-key>" \
  --account sales@example.com

Legacy private app access tokens can also be stored as HUBSPOT_ACCESS_TOKEN, but new single-account REST integrations should prefer Service Keys.

OAuth client credentials are also supported for public app installations:

bash
hybridclaw auth login hubspot \
  --client-id "<hubspot-oauth-client-id>" \
  --client-secret "<hubspot-oauth-client-secret>" \
  --refresh-token "<refresh-token>"

The gateway injects HUBSPOT_ACCESS_TOKEN only when an http_request uses bearerSecretName: "HUBSPOT_ACCESS_TOKEN" against HubSpot API hosts. With OAuth credentials, the gateway mints the access token from HUBSPOT_CLIENT_SECRET and HUBSPOT_REFRESH_TOKEN; with Service Key or legacy private app setup, the stored bearer credential is used directly.

Required HubSpot scopes depend on the task. The default OAuth login scope set covers contacts, companies, deals, notes, tasks, CRM schema reads, and oauth.

Default Workflow

  1. Start with reads or plan. Do not mutate CRM state unless the user clearly asks for the exact write.
  2. Run the bundled helper to build an http_request wrapper:
    bash
    node skills/hubspot/hubspot.cjs ...
  3. Pass only the emitted httpRequest object to the built-in http_request tool when dry-running or when the helper cannot reach the gateway. For live HubSpot reads and writes, use the helper run command so the CJS script owns request construction, gateway submission, and auth-error handling.
  4. Never handcraft HubSpot http_request calls from memory. The helper owns endpoint selection, method, payload, secret refs, and auth-error handling.
  5. For natural-language writes, run workflow first. It emits ordered property metadata, lookup, operator confirmation, and write steps.
  6. For writes, confirm the target record and intended field change, then pass either the exact --grant value or --operator-grant.
  7. Use internal HubSpot IDs for write targets. If a name search returns multiple records, stop and ask for the exact record ID.
  8. Use internal stage values for dealstage, pipeline, and lifecyclestage. Read /crm/v3/properties/... first when the internal value is unknown.
  9. If a live HubSpot call returns 401 or 403, stop after that first failure. Do not retry, do not call more HubSpot endpoints, and do not guess from dates or epoch timestamps. Tell the operator to verify or replace HUBSPOT_ACCESS_TOKEN. For Service Keys, they should copy the current key from HubSpot's Service keys page or rotate it if HubSpot says it was revoked, expired, exposed, or invalid.
Show full SKILL.md (314 more words)Show less

Command Contract

Plan a request without authentication:

bash
node skills/hubspot/hubspot.cjs --format json plan "Move the Acme Renewal deal to contractsent and add a follow-up task"

Build an ordered natural-language workflow:

bash
node skills/hubspot/hubspot.cjs --format json workflow \
  "Move the Acme Renewal deal to contractsent and log a note saying 'Contract sent to legal'"

After selecting the exact deal id from search results, rerun with the record id and exact grant:

bash
node skills/hubspot/hubspot.cjs --format json workflow \
  "Move the Acme Renewal deal to contractsent" \
  --record-id 123456 \
  --grant approve-hubspot-deal-stage-update

Run live read requests:

bash
node skills/hubspot/hubspot.cjs --format json run search contacts --query jane@example.com
node skills/hubspot/hubspot.cjs --format json run search companies --query acme
node skills/hubspot/hubspot.cjs --format json run search deals --query renewal

Build dry-run request payloads without calling HubSpot:

bash
node skills/hubspot/hubspot.cjs --format json http-request list contacts --limit 25
node skills/hubspot/hubspot.cjs --format json http-request list companies --property name --property domain
node skills/hubspot/hubspot.cjs --format json http-request list deals --properties dealname,dealstage,pipeline,amount

Read a record or properties:

bash
node skills/hubspot/hubspot.cjs --format json http-request get deals 123456 --associations contacts,companies
node skills/hubspot/hubspot.cjs --format json http-request properties deals
node skills/hubspot/hubspot.cjs --format json http-request properties contacts

Update a deal stage after explicit grant:

bash
node skills/hubspot/hubspot.cjs --format json http-request update-deal-stage 123456 \
  --stage contractsent \
  --properties-file /tmp/hubspot-deal-properties.json \
  --grant approve-hubspot-deal-stage-update

Update lifecycle stage after explicit grant:

bash
node skills/hubspot/hubspot.cjs --format json http-request update-lifecycle-stage contacts 123456 \
  --stage marketingqualifiedlead \
  --properties-file /tmp/hubspot-contact-properties.json \
  --grant approve-hubspot-lifecycle-stage-update

Validate an internal option value from a saved properties response:

bash
node skills/hubspot/hubspot.cjs --format json validate-option \
  --properties-file /tmp/hubspot-deal-properties.json \
  --property dealstage \
  --value contractsent

Create a note associated with a deal:

bash
node skills/hubspot/hubspot.cjs --format json http-request create-note \
  --body "Spoke with Carla about legal review." \
  --associate-object deals \
  --associate-id 123456 \
  --grant approve-hubspot-note-create

Create a task associated with a contact:

bash
node skills/hubspot/hubspot.cjs --format json http-request create-task \
  --subject "Send procurement packet" \
  --body "Follow up with pricing and security documentation." \
  --due 2026-05-20 \
  --associate-object contacts \
  --associate-id 987654 \
  --grant approve-hubspot-task-create

Run the offline eval suite:

bash
node skills/hubspot/hubspot.cjs --format json eval-scenarios

Explain a HubSpot API error wrapper:

bash
node skills/hubspot/hubspot.cjs --format json explain-error \
  --status 403 \
  --body '{"message":"missing scope crm.objects.deals.write"}'

Working Rules

  • Use http_request; do not use curl for HubSpot API calls when http_request is available.
  • Never print, store in files, or include real HubSpot access tokens in tool arguments or prose.
  • Never infer that a HubSpot token is a "default", "stale", or "1970" value from API timestamps. HubSpot Service Keys, legacy private app tokens, and OAuth tokens are opaque; report only that the stored HUBSPOT_ACCESS_TOKEN was rejected and needs verification or replacement.
  • Treat writes as amber operations and require exact operator grant in the current task.
  • Use exact HubSpot record IDs for writes.
  • Use HubSpot internal option values, not labels, for dealstage, pipeline, and lifecyclestage.
  • Read CRM properties before changing a stage when the internal value is not known.
  • Prefer passing saved property metadata with --properties-file for dealstage and lifecyclestage writes so the helper validates internal option values before emitting a write request.
  • HubSpot lifecycle stage changes can be constrained by HubSpot's lifecycle ordering rules; if the API rejects a backwards move, report the upstream constraint instead of retrying with guessed values.
  • Cost per assistant run is recorded by HybridClaw UsageTotals; helper output includes costMeasurement.system = "UsageTotals" so evals can verify the accounting contract.

Eval Suite

The fixture at evals/scenarios.json contains 30 representative scenarios across contact/company/deal reads, deal stage updates, lifecycle updates, note logging, task creation, and compound requests.

Validation

Run:

bash
node skills/hubspot/hubspot.cjs --help
node skills/hubspot/hubspot.cjs --format json eval-scenarios

© HybridAIOne, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files in skills/hubspot of HybridAIOne/hybridclaw.

  • SKILL.md
  • evals/scenarios.json
  • fixtures/deal-properties.json
  • hubspot-plan.cjs
  • hubspot-requests.cjs
  • hubspot-validation.cjs
  • hubspot.cjs

Open the folder on GitHubat commit 8162701

Compare with similar skills

Hubspot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hubspot compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hubspot this skillHybridAIOne/hybridclaw159—~3kAutomated safety check: PassMIT
Google Maps Exportgmapsscraper/google-maps-agent-skills132—~1.2kAutomated safety check: PassMIT
Lost Deal Revival AgentOthmane-Khadri/YALC-the-GTM-operating-system318—~3kAutomated safety check: PassMIT
HubspotOpenClaudia/openclaudia-skills713—~1.8kAutomated safety check: NotesMIT
Aai Hubspotaai-labs/agent-barn109—~223Automated safety check: PassApache-2.0
Hubspotrefly-ai/refly-skills204—~491Automated safety check: PassNone

Similar skills

  • Google Maps Export

    gmapsscraper/google-maps-agent-skills

    Export Google Maps business data to CSV, JSON, or CRM format (HubSpot, Pipedrive, Salesforce).

    132 GitHub stars~1.2k tokensUpdated 4 mo ago
    Sales & SupportAuto-check passed
  • Lost Deal Revival Agent

    Othmane-Khadri/YALC-the-GTM-operating-system

    Drafts revival messages for closed-lost deals when a public company signal contradicts the original objection.

    318 GitHub stars~3k tokensUpdated 1 mo ago
    Sales & SupportAuto-check passed
  • Hubspot

    OpenClaudia/openclaudia-skills

    Manage HubSpot CRM contacts, companies, deals, and CMS content via API.

    713 GitHub stars~1.8k tokensUpdated 23 days ago
    Sales & SupportAuto-check: notes
  • Aai Hubspot

    aai-labs/agent-barn

    Use aai-cli to inspect HubSpot CRM records, files, events, conversations, visitor identification, and custom channels.

    109 GitHub stars~223 tokensUpdated yesterday
    Sales & SupportAuto-check passed
  • Hubspot

    refly-ai/refly-skills

    Integrate with HubSpot for CRM management. An agent skill from refly-ai/refly-skills.

    204 GitHub stars~491 tokensUpdated 2 mo ago
    Sales & SupportAuto-check passed
  • Hubspot

    Anil-matcha/awesome-muse-connectors

    Read and manage the HubSpot CRM: contacts, contact search, deals.

    1.3k GitHub stars~558 tokensUpdated 5 days ago
    Sales & SupportAuto-check passed

More from HybridAIOne/hybridclaw

All 72 skills in this repo
  • Hermes3000 Writing

    HybridAIOne/hybridclaw

    Use Hermes3000 to plan, draft, revise, save, check consistency, and export long-form manuscripts through the Hermes3000 AI writing portal API.

    159 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Manim Video

    HybridAIOne/hybridclaw

    Plan, script, render, and stitch Manim Community Edition videos in Python.

    159 GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Skill Creator

    HybridAIOne/hybridclaw

    Create and update SKILL.md-based skills with strong trigger metadata, lean docs, and reliable init, validate, package, and publish workflows.

    159 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • XLSX

    HybridAIOne/hybridclaw

    Create, edit, inspect, and analyze .xlsx spreadsheets and Excel workbooks.

    159 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Excalidraw

    HybridAIOne/hybridclaw

    Create and revise editable .excalidraw diagrams as Excalidraw JSON for architecture diagrams, flowcharts, sequence diagrams, concept maps, and other hand-drawn explainers.

    159 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Google Ads

    HybridAIOne/hybridclaw

    Manage Google Ads accounts with safe GAQL reporting, campaign planning, guarded mutations, and gateway-proxied REST API calls.

    159 GitHub stars~4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Hubspot

What does Hubspot do?

Read HubSpot contacts, companies, and deals; update deal stages and lifecycle stages; log notes and tasks through gateway-managed bearer tokens. Hubspot is an agent skill from HybridAIOne/hybridclaw. Read HubSpot contacts, companies, and deals; update deal stages and lifecycle stages; log notes and tasks through gateway-managed bearer tokens.

When should I use Hubspot?

Hubspot fits situations like: tasks that involve CRM management.

How do I install Hubspot in Claude Code?

Run `npx skills add HybridAIOne/hybridclaw --skill hubspot -a claude-code`. Or copy the skill folder (skills/hubspot in HybridAIOne/hybridclaw) into .claude/skills/hubspot in your project. Claude Code loads it when a task matches its description.

How do I install Hubspot in Codex?

Run `npx skills add HybridAIOne/hybridclaw --skill hubspot -a codex`. Or copy the skill folder (skills/hubspot in HybridAIOne/hybridclaw) into .agents/skills/hubspot in your project. Codex loads it when a task matches its description.

Can I use Hubspot in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HybridAIOne/hybridclaw --skill hubspot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hubspot, .gemini/skills/hubspot, .github/skills/hubspot and .opencode/skills/hubspot in your project.

What does Hubspot need to run?

Going by SKILL.md and its folder, Hubspot needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node) and credentials named HUBSPOT_ACCESS_TOKEN, HUBSPOT_CLIENT_SECRET and HUBSPOT_REFRESH_TOKEN. Our summary lists: A credential in HUBSPOT_ACCESS_TOKEN; A credential in HUBSPOT_CLIENT_SECRET.

Does Hubspot access the network?

SKILL.md names 1 domain. As links in the text: developers.hubspot.com. This is read from the text; nothing was executed.

Is Hubspot safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hubspot use?

Hubspot is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hubspot use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hubspot?

Skills that share tags, products or a category with Hubspot: Google Maps Export (gmapsscraper/google-maps-agent-skills, 132 stars), Lost Deal Revival Agent (Othmane-Khadri/YALC-the-GTM-operating-system, 318 stars), Hubspot (OpenClaudia/openclaudia-skills, 713 stars) and Aai Hubspot (aai-labs/agent-barn, 109 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hubspot?

HybridAIOne (a GitHub organization) maintains it in HybridAIOne/hybridclaw, which has 159 GitHub stars. The repository holds 72 skills in this directory. The repository was last updated on October 9, 2026.

Source: HybridAIOne/hybridclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.