Agent skill

Customerio Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Apply Customer.io security best practices. An agent skill from jeremylongshore/tons-of-skills-marketplace.

MITAuto-check: notesLegal & Compliance

Install Customerio Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill customerio-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace customerio-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/customerio-security-basics .claude/skills/customerio-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
customerio-security-basics
GitHub stars
2.8k
Token cost
~2.4k tokens
SKILL.md length
289 words
Files
3 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Apply Customer.io security best practices. An agent skill from jeremylongshore/tons-of-skills-marketplace.

  • Works in 5 steps: Secure Credential Storage → PII Sanitization → Webhook Signature Verification → …
  • Implementing secure credential storage
  • SKILL.md covers Output, Examples, Overview and Prerequisites, plus 5 more sections
  • Needs CUSTOMERIO_TRACK_API_KEY and WEBHOOK_SECRET

What it does

Customerio Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Apply Customer.io security best practices. Use when implementing secure credential storage, PII handling, webhook signature verification, or GDPR/CCPA compliance. Trigger: "customer.io security", "customer.io pii", "secure customer.io", "customer.io gdpr", "customer.io webhook verify".

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/implementation-guide.md` and `references/implementation.md`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Privacy and GDPR and Webhooks. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Implementing secure credential storage
  • Webhook signature verification
  • GDPR/CCPA compliance

Example prompts

  • “customer.io security”
  • “customer.io pii”
  • “secure customer.io”
  • “/customerio-security-basics”

Requirements

  • A credential in CUSTOMERIO_TRACK_API_KEY
  • A credential in WEBHOOK_SECRET
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(npm:*), Glob, Grep

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Secure Credential Storage
  2. PII Sanitization
  3. Webhook Signature Verification
  4. API Key Rotation
  5. GDPR/CCPA Data Deletion

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(npm:*)
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • customer.io
    • docs.customer.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CUSTOMERIO_TRACK_API_KEY
    • WEBHOOK_SECRET
    • CUSTOMERIO_WEBHOOK_SECRET
    • NEW_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Customerio Security Basics loads about 2.4k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 78 tokens; SKILL.md has 289 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:267
    API keys stored in secrets manager (not `.env` in production)
  • NoteMentions a .env fileSKILL.md:273
    - [ ] `.env` files in `.gitignore`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 289 words, ~2,363 tokens.

Download SKILL.mdSave it as .claude/skills/customerio-security-basics/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
customerio-security-basics
description
Apply Customer.io security best practices. Use when implementing secure credential storage, PII handling, webhook signature verification, or GDPR/CCPA compliance. Trigger: "customer.io security", "customer.io pii", "secure customer.io", "customer.io gdpr", "customer.io webhook verify".
allowed-tools
Read, Write, Edit, Bash(npm:*), Glob, Grep
compatibility
Designed for Claude Code
version
1.14.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, customer-io, security, gdpr, compliance

Customer.io Security Basics

Output

  • A least-privilege Customer.io integration with scoped secrets, approved data attributes, and auditable access ownership.
  • A tested incident path for credential exposure, unauthorized delivery, and sensitive-data handling.

Examples

Configure a development workspace secret through the approved manager and send a synthetic event that contains no recipient PII. Verify the event uses the intended workspace and attribute allowlist. If a token or customer attribute appears in source or logs, revoke/contain first, then investigate and replace it.

Overview

Implement security best practices for Customer.io: secrets management for API credentials, PII sanitization before sending data, webhook signature verification (HMAC-SHA256), API key rotation, and GDPR/CCPA data deletion compliance.

Prerequisites

  • Customer.io account with admin access
  • Understanding of your data classification (what is PII)
  • Secrets management system (recommended for production)

Instructions

Step 1: Secure Credential Storage
typescript
// lib/customerio-secrets.ts
// NEVER hardcode credentials — use environment variables or a secrets manager

// Option A: Environment variables (acceptable for most apps)
const siteId = process.env.CUSTOMERIO_SITE_ID;
const trackKey = process.env.CUSTOMERIO_TRACK_API_KEY;

// Option B: GCP Secret Manager (recommended for production)
import { SecretManagerServiceClient } from "@google-cloud/secret-manager";

const secretClient = new SecretManagerServiceClient();

async function getSecret(name: string): Promise<string> {
  const [version] = await secretClient.accessSecretVersion({
    name: `projects/my-project/secrets/${name}/versions/latest`,
  });
  return version.payload?.data?.toString() ?? "";
}

async function createCioClient() {
  const [siteId, trackKey] = await Promise.all([
    getSecret("customerio-site-id"),
    getSecret("customerio-track-api-key"),
  ]);

  return new TrackClient(siteId, trackKey, { region: RegionUS });
}
Step 2: PII Sanitization
typescript
// lib/customerio-sanitize.ts
// Sanitize user data BEFORE sending to Customer.io

const NEVER_SEND = new Set([
  "ssn", "social_security", "tax_id",
  "credit_card", "card_number", "cvv",
  "password", "password_hash",
  "bank_account", "routing_number",
]);

const HASH_FIELDS = new Set([
  "phone", "phone_number",
  "ip_address", "ip",
  "address", "street_address",
]);

import { createHash } from "crypto";

function hashValue(value: string): string {
  return createHash("sha256").update(value).digest("hex").substring(0, 16);
}

export function sanitizeAttributes(
  attrs: Record<string, any>
): Record<string, any> {
  const clean: Record<string, any> = {};

  for (const [key, value] of Object.entries(attrs)) {
    const lowerKey = key.toLowerCase();

    // Strip highly sensitive fields entirely
    if (NEVER_SEND.has(lowerKey)) continue;

    // Hash PII fields
    if (HASH_FIELDS.has(lowerKey) && typeof value === "string") {
      clean[`${key}_hash`] = hashValue(value);
      continue;
    }

    clean[key] = value;
  }

  return clean;
}

// Usage
import { TrackClient, RegionUS } from "customerio-node";

const cio = new TrackClient(siteId, trackKey, { region: RegionUS });

await cio.identify("user-123", sanitizeAttributes({
  email: "user@example.com",         // Kept (needed for email delivery)
  first_name: "Jane",                // Kept
  phone: "+1-555-0123",              // Hashed → phone_hash
  ssn: "123-45-6789",                // STRIPPED entirely
  plan: "pro",                       // Kept
}));
Step 3: Webhook Signature Verification

Customer.io signs webhook payloads with HMAC-SHA256. Always verify before processing.

typescript
// middleware/customerio-webhook.ts
import { createHmac, timingSafeEqual } from "crypto";
import { Request, Response, NextFunction } from "express";

const WEBHOOK_SECRET = process.env.CUSTOMERIO_WEBHOOK_SECRET!;

export function verifyCioWebhook(
  req: Request,
  res: Response,
  next: NextFunction
): void {
  const signature = req.headers["x-cio-signature"] as string;
  if (!signature) {
    res.status(401).json({ error: "Missing signature header" });
    return;
  }

  // req.body must be the raw buffer — configure Express accordingly
  const rawBody = (req as any).rawBody as Buffer;
  if (!rawBody) {
    res.status(500).json({ error: "Raw body not available" });
    return;
  }

  const expected = createHmac("sha256", WEBHOOK_SECRET)
    .update(rawBody)
    .digest("hex");

  const valid = timingSafeEqual(
    Buffer.from(signature),
    Buffer.from(expected)
  );

  if (!valid) {
    res.status(401).json({ error: "Invalid signature" });
    return;
  }

  next();
}

// Express setup — raw body required for signature verification
import express from "express";
const app = express();

app.use("/webhooks/customerio", express.raw({ type: "application/json" }));
app.post("/webhooks/customerio", verifyCioWebhook, (req, res) => {
  const event = JSON.parse((req as any).rawBody.toString());
  // Process verified webhook event
  res.sendStatus(200);
});
Step 4: API Key Rotation
typescript
// scripts/rotate-cio-keys.ts
// Rotation procedure — zero downtime

async function rotateKeys() {
  console.log("Customer.io Key Rotation Procedure:");
  console.log("1. Go to Settings > Workspace Settings > API & Webhook Credentials");
  console.log("2. Click 'Regenerate' next to the key you want to rotate");
  console.log("3. Copy the NEW key");
  console.log("4. Update your secrets manager:");
  console.log("   - GCP: gcloud secrets versions add customerio-track-api-key --data-file=-");
  console.log("   - AWS: aws ssm put-parameter --name /cio/track-api-key --value NEW_KEY --overwrite");
  console.log("5. Deploy your application (or restart to pick up new secrets)");
  console.log("6. Verify: run the connectivity test script");
  console.log("7. The old key is immediately invalidated upon regeneration");
  console.log("");
  console.log("IMPORTANT: Regenerating a key IMMEDIATELY invalidates the old key.");
  console.log("Update secrets BEFORE regenerating, or plan for brief downtime.");
}
Step 5: GDPR/CCPA Data Deletion
typescript
// services/customerio-gdpr.ts
import { TrackClient, RegionUS } from "customerio-node";

const cio = new TrackClient(
  process.env.CUSTOMERIO_SITE_ID!,
  process.env.CUSTOMERIO_TRACK_API_KEY!,
  { region: RegionUS }
);

// GDPR Right to Erasure / CCPA Delete My Data
async function handleDeletionRequest(userId: string): Promise<void> {
  // 1. Suppress — stop all messaging immediately
  await cio.suppress(userId);
  console.log(`User ${userId} suppressed (no more messages)`);

  // 2. Destroy — remove profile and all data from Customer.io
  await cio.destroy(userId);
  console.log(`User ${userId} deleted from Customer.io`);

  // 3. Log the deletion for compliance audit trail
  console.log(`GDPR deletion completed for ${userId} at ${new Date().toISOString()}`);
}

// Bulk deletion (e.g., processing deletion requests from a queue)
async function bulkDelete(userIds: string[]): Promise<void> {
  for (const userId of userIds) {
    try {
      await handleDeletionRequest(userId);
    } catch (err: any) {
      // Log but continue — don't let one failure block others
      console.error(`Deletion failed for ${userId}: ${err.message}`);
    }
    // Respect rate limits
    await new Promise((r) => setTimeout(r, 100));
  }
}

Security Checklist

  • API keys stored in secrets manager (not .env in production)
  • API key rotation schedule set (every 90 days)
  • Webhook signatures verified (HMAC-SHA256 with timingSafeEqual)
  • PII sanitized before sending to Customer.io
  • Highly sensitive data (SSN, credit card) never sent
  • GDPR deletion endpoint implemented (suppress + destroy)
  • .env files in .gitignore
  • Audit log for deletion requests
  • Minimum necessary data principle applied

Error Handling

IssueSolution
Credentials exposed in gitRotate immediately, scan git history with trufflehog
PII accidentally sentDelete user with destroy(), update sanitization rules
Webhook signature mismatchVerify webhook secret matches Customer.io dashboard
Key rotation causes downtimeUpdate secrets manager BEFORE regenerating in dashboard

Resources

Next Steps

After implementing security, proceed to customerio-prod-checklist for production readiness.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/.curated/customerio-security-basics of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/implementation-guide.md
  • references/implementation.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Customerio Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Customerio Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Customerio Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.4kAutomated safety check: NotesMIT
Privacy Pagamenticcplugins/awesome-claude-code-plugins970—~845Automated safety check: PassApache-2.0
Email Best Practicesviclafouch/meme-studio1107 repos~787Automated safety check: PassNone
Eu Data Act Oliver Schmidt Prietzlawve-ai/awesome-legal-skills847—~3.9kAutomated safety check: PassAGPL-3.0
Healthcare Phi Complianceaffaan-m/ECC277k1 repos~1.4kAutomated safety check: PassMIT
Auto Data Discoverymukul975/Privacy-Data-Protection-Skills301—~3.3kAutomated safety check: PassApache-2.0

Similar skills

  • Privacy Pagamenti

    ccplugins/awesome-claude-code-plugins

    Protegge dati di pagamento e abbonamenti quando un sito/app gestisce checkout, carte, subscription o fatturazione.

    970 GitHub stars~845 tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Email Best Practices

    viclafouch/meme-studio

    A skill your agent uses when building email features, emails going to spam, high bounce rates, setting up SPF/DKIM/DMARC authentication, implementing email capture, ensuring compliance (CAN-SPAM…

    110 GitHub starsUsed in 7 repos~787 tokens
    Backend & APIsAuto-check passed
  • Eu Data Act Oliver Schmidt Prietz

    lawve-ai/awesome-legal-skills

    Practitioner skill for advising on EU Regulation 2023/2854 (Data Act).

    847 GitHub stars~3.9k tokensUpdated 8 days ago
    Legal & ComplianceAuto-check passed
  • Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…

    277k GitHub starsUsed in 1 repo~1.4k tokens
    Legal & ComplianceAuto-check passed
  • Auto Data Discovery

    mukul975/Privacy-Data-Protection-Skills

    Implements automated PII discovery and classification using tools like Microsoft Purview, BigID, OneTrust DataDiscovery, and AWS Macie.

    301 GitHub stars~3.3k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Cloud Retention Config

    mukul975/Privacy-Data-Protection-Skills

    Configures cloud storage retention policies across AWS S3, Azure Blob Storage, and Google Cloud Storage.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Customerio Security Basics

What does Customerio Security Basics do?

Apply Customer.io security best practices. An agent skill from jeremylongshore/tons-of-skills-marketplace. Customerio Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace.io security best practices.

When should I use Customerio Security Basics?

Customerio Security Basics fits situations like: implementing secure credential storage; webhook signature verification; GDPR/CCPA compliance.

How do I install Customerio Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill customerio-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/customerio-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/customerio-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Customerio Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill customerio-security-basics -a codex`. Or copy the skill folder (skills/.curated/customerio-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/customerio-security-basics in your project. Codex loads it when a task matches its description.

Can I use Customerio Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill customerio-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/customerio-security-basics, .gemini/skills/customerio-security-basics, .github/skills/customerio-security-basics and .opencode/skills/customerio-security-basics in your project.

What does Customerio Security Basics need to run?

Going by SKILL.md and its folder, Customerio Security Basics needs credentials named CUSTOMERIO_TRACK_API_KEY, WEBHOOK_SECRET, CUSTOMERIO_WEBHOOK_SECRET and NEW_KEY. Our summary lists: A credential in CUSTOMERIO_TRACK_API_KEY; A credential in WEBHOOK_SECRET. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(npm:*), Glob, Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Customerio Security Basics access the network?

SKILL.md names 2 domains. As links in the text: customer.io and docs.customer.io. This is read from the text; nothing was executed.

Is Customerio Security Basics safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Customerio Security Basics use?

Customerio Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Customerio Security Basics use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Customerio Security Basics?

Skills that share tags, products or a category with Customerio Security Basics: Privacy Pagamenti (ccplugins/awesome-claude-code-plugins, 970 stars), Email Best Practices (viclafouch/meme-studio, 110 stars), Eu Data Act Oliver Schmidt Prietz (lawve-ai/awesome-legal-skills, 847 stars) and Healthcare Phi Compliance (affaan-m/ECC, 277k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Customerio Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.