Agent skill

Apify Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Secure Apify API tokens, configure proxy access, and protect Actor data.

MITAuto-check: notesData & Analytics

Install Apify Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill apify-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace apify-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/apify-security-basics .claude/skills/apify-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
apify-security-basics
GitHub stars
2.8k
Token cost
~1.4k tokens
SKILL.md length
562 words
Files
3 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Secure Apify API tokens, configure proxy access, and protect Actor data.

  • Works in 6 steps: Secure token storage — keep the token in… → Per-environment token isolation —… → Token rotation — generate the new token… → …
  • Hardening API key management
  • SKILL.md covers Overview, Prerequisites, Token Architecture and Instructions, plus 7 more sections
  • Calls git, gh and vercel; needs APIFY_TOKEN

What it does

Apify Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Secure Apify API tokens, configure proxy access, and protect Actor data. Use when hardening API key management, setting up environment-specific tokens, rotating a leaked token, or auditing Apify security configuration. Trigger with "apify security", "apify secrets", "secure apify token", "apify API key security", "rotate apify token".

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/examples.md` and `references/implementation.md`). Compatibility notes: Designed for Claude Code

It sits in Data & Analytics, covering Web scraping. It works with Apify. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Hardening API key management
  • Setting up environment-specific tokens
  • Rotating a leaked token
  • Auditing Apify security configuration

Example prompts

  • “apify security”
  • “apify secrets”
  • “secure apify token”
  • “/apify-security-basics”

Requirements

  • A credential in APIFY_TOKEN
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Secure token storage — keep the token in .env (never hardcoded) and add
  2. Per-environment token isolation — separate tokens (ideally separate
  3. Token rotation — generate the new token first (old stays valid), push to
  4. Webhook payload verification — Apify does not sign webhooks; confirm the
  5. Actor data security — redact sensitive fields before pushData; keep
  6. Proxy security — never log proxyConfig.newUrl() (it embeds the proxy

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • vercel

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.apify.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • APIFY_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Apify Security Basics loads about 1.4k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 90 tokens; SKILL.md has 562 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:47
    ure token storage** — keep the token in `.env` (never hardcoded) and add
  • NoteMentions a .env fileSKILL.md:48
    `.env`, `.env.*.local`, and `storage/` to `.gitignore`. Validate presence at
  • NoteMentions a .env fileSKILL.md:81
    - A `.gitignore` that excludes `.env*` and `storage/`, with no token in the tree.
  • NoteMentions a .env fileSKILL.md:91
    - [ ] `.env` and `storage/` in `.gitignore`
  • NoteMentions a .env fileSKILL.md:125
    .env
  • NoteMentions a .env fileSKILL.md:126
    .env.*.local
  • NoteMentions a .env fileSKILL.md:129
    echo 'APIFY_TOKEN=apify_api_dev_token' > .env
  • NoteMentions a .env fileSKILL.md:130
    git status --short   # .env must NOT appear

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 562 words, ~1,441 tokens.

Download SKILL.mdSave it as .claude/skills/apify-security-basics/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
apify-security-basics
description
Secure Apify API tokens, configure proxy access, and protect Actor data. Use when hardening API key management, setting up environment-specific tokens, rotating a leaked token, or auditing Apify security configuration. Trigger with "apify security", "apify secrets", "secure apify token", "apify API key security", "rotate apify token".
allowed-tools
Read, Write, Edit, Grep
compatibility
Designed for Claude Code
version
1.5.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, scraping, automation, apify

Apify Security Basics

Overview

Security best practices for Apify API tokens, Actor data, proxy credentials, and webhook verification. Apify uses personal API tokens (prefixed apify_api_) for all authentication. Because a single token grants full account access with no per-token scoping, token hygiene is the whole game.

Prerequisites

  • Apify account with Console access
  • Understanding of environment variables
  • Access to your deployment platform's secrets management

Token Architecture

Apify uses a single API token per user account for full API access. There is no scope-based permission system per token, so token security is critical.

Token TypeFormatWhere to Find
Personal API tokenapify_api_...Console > Settings > Integrations
Proxy passwordAlphanumericConsole > Proxy > Connection settings

Instructions

Follow the six hardening steps in order. Each has a lean summary below; the full copy-paste code for every step is in references/implementation.md.

  1. Secure token storage — keep the token in .env (never hardcoded) and add .env, .env.*.local, and storage/ to .gitignore. Validate presence at startup so the app fails fast:

    typescript
    function requireToken(): string {
      const token = process.env.APIFY_TOKEN;
      if (!token) throw new Error('APIFY_TOKEN is required');
      if (!token.startsWith('apify_api_')) console.warn('unexpected token prefix');
      return token;
    }
  2. Per-environment token isolation — separate tokens (ideally separate accounts) for dev / staging / prod, injected via each platform's secret store (gh secret set, vercel env add, GCP Secret Manager).

  3. Token rotation — generate the new token first (old stays valid), push to every environment, verify it authenticates, then revoke the old one.

  4. Webhook payload verification — Apify does not sign webhooks; confirm the run ID in the payload actually exists, or gate on a shared URL secret compared with crypto.timingSafeEqual.

  5. Actor data security — redact sensitive fields before pushData; keep datasets named and private (no public sharing).

  6. Proxy security — never log proxyConfig.newUrl() (it embeds the proxy password); log the proxy group only.

See references/implementation.md for the complete code of every step, and references/examples.md for end-to-end scenarios.

Output

Applying this skill produces a hardened project state:

  • A .gitignore that excludes .env* and storage/, with no token in the tree.
  • A startup token validator that throws on a missing/malformed APIFY_TOKEN.
  • Environment-specific tokens wired into each platform's secret store.
  • A documented rotation procedure and a completed Security Checklist (below).
  • Webhook handlers that reject unverified runs and pipelines that redact PII before storage.
Show full SKILL.md (210 more words)Show less

Security Checklist

  • APIFY_TOKEN stored in environment variables (never hardcoded)
  • .env and storage/ in .gitignore
  • Separate tokens for dev/staging/prod
  • Token rotation schedule documented
  • Webhook endpoints verify source
  • Proxy URLs never logged
  • Scraped PII redacted before storage
  • Named datasets used for sensitive data (no public sharing)
  • CI/CD secrets configured (not in repo)

Leaked Token Response

If a token is exposed:

  1. Immediately regenerate token in Console > Settings > Integrations
  2. Check recent Actor runs for unauthorized usage
  3. Review billing for unexpected charges
  4. Rotate proxy password if exposed
  5. Audit git history: git log --all -p -- '*.env' '*.json' | grep apify_api_

Error Handling

IssueDetectionMitigation
Token in git historygit log -p | grep apify_api_Rotate token, use BFG to clean
Unauthorized runsUnexpected runs in ConsoleRotate token immediately
Proxy password exposedCredentials in logsRegenerate proxy password
Data breach in datasetPII in public datasetDelete dataset, sanitize pipeline

Examples

Quick starting point — bootstrap a new project's secrets safely:

bash
cat >> .gitignore <<'EOF'
.env
.env.*.local
storage/
EOF
echo 'APIFY_TOKEN=apify_api_dev_token' > .env
git status --short   # .env must NOT appear

Four full worked scenarios — secure bootstrap, cross-environment rotation, webhook-verify-then-sanitize, and a git-history leak audit — are in references/examples.md.

Resources

Next Steps

For production deployment hardening beyond secrets — health checks, rate limits, and monitoring — see the apify-prod-checklist skill in this pack.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/.curated/apify-security-basics of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/examples.md
  • references/implementation.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Apify Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Apify Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Apify Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.4kAutomated safety check: NotesMIT
Reddit Post Findergooseworks-ai/goose-skills1.2k1 repos~1.2kAutomated safety check: PassMIT
Apify CLIapify/apify-cli256—~1.5kAutomated safety check: PassApache-2.0
Apify Collectextrasmall0/dear-hiring-manager111—~1.1kAutomated safety check: NotesMIT
Apify Lead Scoring Enrichmentapify/awesome-skills266—~4.4kAutomated safety check: NotesApache-2.0
Carousel Benchmarknestyme/awesome-prompts151—~2.6kAutomated safety check: NotesNone

Similar skills

  • Reddit Post Finder

    gooseworks-ai/goose-skills

    Scrape and search Reddit posts using Apify. An agent skill from gooseworks-ai/goose-skills.

    1.2k GitHub starsUsed in 1 repo~1.2k tokens
    Data & AnalyticsAuto-check passed
  • Apify CLI

    apify/apify-cli

    Official

    Patterns for invoking the Apify CLI (apify) from agents. An agent skill from apify/apify-cli.

    256 GitHub stars~1.5k tokensUpdated yesterday
    Data & AnalyticsAuto-check passed
  • Apify Collect

    extrasmall0/dear-hiring-manager

    Collect fresh job-posting URLs into ~/.dear-hiring-manager/urls.txt by running an Apify job scraper — the discovery source for /batch.

    111 GitHub stars~1.1k tokensUpdated 2 mo ago
    Data & AnalyticsAuto-check: notes
  • Apify Lead Scoring Enrichment

    apify/awesome-skills

    Official

    Score and enrich a CSV of B2B leads using Apify Actors. An agent skill from apify/awesome-skills.

    266 GitHub stars~4.4k tokensUpdated 18 days ago
    Data & AnalyticsAuto-check: notes
  • Carousel Benchmark

    nestyme/awesome-prompts

    Find the TikTok photo-mode carousels (slideshows) that actually go viral in a niche and the accounts behind them, rank them by organic quality (save-rate, like-rate, boost detection) instead of raw…

    151 GitHub stars~2.6k tokensUpdated 10 days ago
    Data & AnalyticsAuto-check: notes
  • Blog Feed Monitor

    gooseworks-ai/goose-skills

    Scrape blog posts via RSS feeds (free, no API key) with Apify fallback for JS-heavy sites.

    1.2k GitHub starsUsed in 1 repo~578 tokens
    Data & AnalyticsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated yesterday
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Apify Security Basics

What does Apify Security Basics do?

Secure Apify API tokens, configure proxy access, and protect Actor data. Apify Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Secure Apify API tokens, configure proxy access, and protect Actor data.

When should I use Apify Security Basics?

Apify Security Basics fits situations like: hardening API key management; setting up environment-specific tokens; rotating a leaked token; auditing Apify security configuration.

How do I install Apify Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill apify-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/apify-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/apify-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Apify Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill apify-security-basics -a codex`. Or copy the skill folder (skills/.curated/apify-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/apify-security-basics in your project. Codex loads it when a task matches its description.

Can I use Apify Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill apify-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/apify-security-basics, .gemini/skills/apify-security-basics, .github/skills/apify-security-basics and .opencode/skills/apify-security-basics in your project.

What does Apify Security Basics need to run?

Going by SKILL.md and its folder, Apify Security Basics needs the command-line tools its instructions call (git, gh and vercel) and credentials named APIFY_TOKEN. Our summary lists: A credential in APIFY_TOKEN. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Apify Security Basics access the network?

SKILL.md names 1 domain. As links in the text: docs.apify.com. This is read from the text; nothing was executed.

Is Apify Security Basics safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Apify Security Basics use?

Apify Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Apify Security Basics use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Apify Security Basics?

Skills that share tags, products or a category with Apify Security Basics: Reddit Post Finder (gooseworks-ai/goose-skills, 1.2k stars), Apify CLI (apify/apify-cli, 256 stars), Apify Collect (extrasmall0/dear-hiring-manager, 111 stars) and Apify Lead Scoring Enrichment (apify/awesome-skills, 266 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Apify Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.