Agent skill

Deepgram Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Apply Deepgram security best practices for API key management and data protection.

MITAuto-check passedSecurity

Install Deepgram Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill deepgram-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace deepgram-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/deepgram-security-basics .claude/skills/deepgram-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deepgram-security-basics
GitHub stars
2.8k
Token cost
~2.2k tokens
SKILL.md length
285 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Apply Deepgram security best practices for API key management and data protection.

  • Works in 6 steps: Scoped API Keys → Deepgram Built-in PII Redaction → Temporary Keys for Client-Side → …
  • Securing Deepgram integrations
  • SKILL.md covers Prerequisites, Examples, Overview and Security Checklist, plus 4 more sections
  • Needs DEEPGRAM_API_KEY and DEEPGRAM_ADMIN_KEY

What it does

Deepgram Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Apply Deepgram security best practices for API key management and data protection. Use when securing Deepgram integrations, implementing key rotation, or auditing security configurations. Trigger: "deepgram security", "deepgram API key security", "secure deepgram", "deepgram key rotation", "deepgram data protection", "deepgram PII redaction".

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/implementation.md`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Privacy and GDPR, Cryptography and Security review. It works with Deepgram. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Securing Deepgram integrations
  • Implementing key rotation
  • Auditing security configurations

Example prompts

  • “deepgram security”
  • “deepgram API key security”
  • “secure deepgram”
  • “/deepgram-security-basics”

Requirements

  • A credential in DEEPGRAM_STT_KEY
  • A credential in DEEPGRAM_TTS_KEY
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Bash(curl:*)

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Scoped API Keys
  2. Deepgram Built-in PII Redaction
  3. Temporary Keys for Client-Side
  4. Key Rotation
  5. Audio URL Validation (SSRF Prevention)
  6. Audit Logging

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Bash(curl:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.deepgram.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DEEPGRAM_API_KEY
    • DEEPGRAM_ADMIN_KEY
    • DEEPGRAM_STT_KEY
    • DEEPGRAM_TTS_KEY
    • DEEPGRAM_MONITOR_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Deepgram Security Basics loads about 2.2k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 285 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 285 words, ~2,187 tokens.

Download SKILL.mdSave it as .claude/skills/deepgram-security-basics/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
deepgram-security-basics
description
Apply Deepgram security best practices for API key management and data protection. Use when securing Deepgram integrations, implementing key rotation, or auditing security configurations. Trigger: "deepgram security", "deepgram API key security", "secure deepgram", "deepgram key rotation", "deepgram data protection", "deepgram PII redaction".
allowed-tools
Read, Write, Edit, Grep, Bash(curl:*)
compatibility
Designed for Claude Code
version
1.13.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, deepgram, api, security, compliance

Deepgram Security Basics

Prerequisites

  • A data classification and consent decision for the audio/transcript workload.
  • Scoped project credentials in the approved secret manager, an owner, and an incident/revocation route.

Examples

Use a development credential and a licensed non-sensitive audio fixture to verify the integration, logging only an opaque request ID and outcome. If recordings, transcripts, or keys are exposed, restrict access, revoke credentials where applicable, and follow the organization’s incident process before continuing.

Overview

Security best practices for Deepgram integration: scoped API keys, key rotation, Deepgram's built-in PII redaction feature, client-side temporary keys, SSRF prevention for audio URLs, and audit logging.

Security Checklist

  • API keys in environment variables or secret manager (never in code)
  • Separate keys per environment (dev/staging/prod)
  • Keys scoped to minimum required permissions
  • Key rotation schedule (90 days recommended)
  • Deepgram redact option enabled for PII-sensitive audio
  • Audio URLs validated (HTTPS only, no private IPs)
  • Audit logging on all transcription operations

Instructions

Step 1: Scoped API Keys

Create keys with minimal permissions in Console > Settings > API Keys:

typescript
// Production transcription service — only needs listen scope
const sttKey = process.env.DEEPGRAM_STT_KEY;  // Scope: listen

// TTS service — only needs speak scope
const ttsKey = process.env.DEEPGRAM_TTS_KEY;  // Scope: speak

// Monitoring dashboard — only needs usage read
const monitorKey = process.env.DEEPGRAM_MONITOR_KEY;  // Scope: usage:read

// Admin operations — separate key, restricted access
const adminKey = process.env.DEEPGRAM_ADMIN_KEY;  // Scope: manage, keys
Step 2: Deepgram Built-in PII Redaction
typescript
import { createClient } from '@deepgram/sdk';

const deepgram = createClient(process.env.DEEPGRAM_API_KEY!);

// Deepgram redacts PII directly in the transcript
const { result } = await deepgram.listen.prerecorded.transcribeUrl(
  { url: audioUrl },
  {
    model: 'nova-3',
    smart_format: true,
    // Built-in redaction — replaces sensitive data in transcript
    redact: ['pci', 'ssn', 'numbers'],
    // pci     — Credit card numbers → [REDACTED]
    // ssn     — Social Security numbers → [REDACTED]
    // numbers — All numeric sequences → [REDACTED]
  }
);

// Transcript will contain [REDACTED] in place of sensitive numbers
console.log(result.results.channels[0].alternatives[0].transcript);
// "My card number is [REDACTED] and my SSN is [REDACTED]"
Step 3: Temporary Keys for Client-Side
typescript
// Generate short-lived keys for browser/mobile clients
// This prevents exposing your main API key

import { createClient } from '@deepgram/sdk';
import express from 'express';

const app = express();
const deepgram = createClient(process.env.DEEPGRAM_API_KEY!);

app.post('/api/deepgram/token', async (req, res) => {
  // Create a temporary key that expires in 10 seconds
  // Use for browser WebSocket connections
  const { result, error } = await deepgram.manage.createProjectKey(
    process.env.DEEPGRAM_PROJECT_ID!,
    {
      comment: `temp-key-${Date.now()}`,
      scopes: ['listen'],          // Minimal scope
      time_to_live_in_seconds: 10, // Short-lived
    }
  );

  if (error) return res.status(500).json({ error: error.message });
  res.json({ key: result.key, expires_in: 10 });
});

// Browser client uses temporary key:
// const { key } = await fetch('/api/deepgram/token').then(r => r.json());
// const ws = new WebSocket('wss://api.deepgram.com/v1/listen', ['token', key]);
Step 4: Key Rotation
typescript
import { createClient } from '@deepgram/sdk';

async function rotateApiKey(projectId: string) {
  const admin = createClient(process.env.DEEPGRAM_ADMIN_KEY!);

  // 1. Create new key with same scopes
  const { result: newKey } = await admin.manage.createProjectKey(projectId, {
    comment: `rotated-${new Date().toISOString().split('T')[0]}`,
    scopes: ['listen', 'speak'],
    expiration_date: new Date(Date.now() + 90 * 86400000).toISOString(), // 90 days
  });
  console.log('New key created:', newKey.key_id);

  // 2. Update secret manager (example: GCP Secret Manager)
  // await updateSecret('DEEPGRAM_API_KEY', newKey.key);

  // 3. Validate new key works
  const testClient = createClient(newKey.key);
  const { error } = await testClient.manage.getProjects();
  if (error) throw new Error('New key validation failed — aborting rotation');

  // 4. Delete old key (after services have picked up new key)
  // await admin.manage.deleteProjectKey(projectId, oldKeyId);

  return newKey;
}
Step 5: Audio URL Validation (SSRF Prevention)
typescript
import { URL } from 'url';
import { lookup } from 'dns/promises';

async function validateAudioUrl(url: string): Promise<void> {
  const parsed = new URL(url);

  // Require HTTPS
  if (parsed.protocol !== 'https:') {
    throw new Error('Only HTTPS audio URLs allowed');
  }

  // Block private/internal IPs
  const { address } = await lookup(parsed.hostname);
  const privateRanges = [
    /^127\./, /^10\./, /^172\.(1[6-9]|2\d|3[01])\./, /^192\.168\./,
    /^0\./, /^169\.254\./, /^::1$/, /^fc00:/, /^fe80:/,
  ];
  if (privateRanges.some(r => r.test(address))) {
    throw new Error(`Blocked: ${parsed.hostname} resolves to private IP`);
  }

  // Block known internal hostnames
  const blockedHosts = ['localhost', 'metadata.google.internal', '169.254.169.254'];
  if (blockedHosts.includes(parsed.hostname)) {
    throw new Error(`Blocked hostname: ${parsed.hostname}`);
  }
}

// Use before transcription:
await validateAudioUrl(userProvidedUrl);
const { result } = await deepgram.listen.prerecorded.transcribeUrl(
  { url: userProvidedUrl }, { model: 'nova-3' }
);
Step 6: Audit Logging
typescript
interface AuditEntry {
  timestamp: string;
  action: 'transcribe' | 'tts' | 'key_create' | 'key_delete';
  userId: string;
  requestId?: string;
  model: string;
  audioDuration?: number;
  success: boolean;
  error?: string;
  ip?: string;
}

function logAudit(entry: AuditEntry) {
  // Structured JSON for log aggregation (Datadog, CloudWatch, etc.)
  const log = {
    ...entry,
    service: 'deepgram-integration',
    level: entry.success ? 'info' : 'error',
  };
  console.log(JSON.stringify(log));
}

// Usage in transcription middleware
async function transcribeWithAudit(userId: string, url: string, ip: string) {
  const start = Date.now();
  try {
    const { result, error } = await deepgram.listen.prerecorded.transcribeUrl(
      { url }, { model: 'nova-3', smart_format: true }
    );
    logAudit({
      timestamp: new Date().toISOString(),
      action: 'transcribe',
      userId, model: 'nova-3', ip,
      requestId: result?.metadata?.request_id,
      audioDuration: result?.metadata?.duration,
      success: !error,
      error: error?.message,
    });
    if (error) throw error;
    return result;
  } catch (err: any) {
    logAudit({
      timestamp: new Date().toISOString(),
      action: 'transcribe',
      userId, model: 'nova-3', ip,
      success: false, error: err.message,
    });
    throw err;
  }
}

Output

  • Scoped API keys per service/environment
  • Built-in PII redaction via redact parameter
  • Temporary keys for client-side (browser/mobile)
  • Key rotation with validation and cleanup
  • SSRF-safe audio URL validation
  • Structured audit logging

Error Handling

IssueCauseSolution
403 after scopingKey missing required scopeAdd scope in Console (e.g., listen)
Temp key expiredTTL too shortIncrease time_to_live_in_seconds
Rotation broke serviceNew key not propagatedUse overlap period — both keys active
Redaction missed PIIWrong redact optionUse redact: ['pci', 'ssn', 'numbers']

Resources

  • API Key Management
  • PII Redaction
  • Deepgram Security
  • SOC 2 / HIPAA

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/deepgram-security-basics of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/implementation.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Deepgram Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deepgram Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deepgram Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.2kAutomated safety check: PassMIT
Security Reviewvalory-xyz/open-autonomy129—~11kAutomated safety check: NotesApache-2.0
Implementing Aes Encryption For Data At RESTmukul975/Anthropic-Cybersecurity-Skills34k—~1.1kAutomated safety check: PassApache-2.0
Performing Ssl Tls Inspection Configurationmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: NotesApache-2.0
Security Review Specwarpdotdev/oz-for-oss3121 repos~2.6kAutomated safety check: PassMIT
SecurityOpenHands/extensions163—~342Automated safety check: PassMIT

Similar skills

  • Security Review

    valory-xyz/open-autonomy

    Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment…

    129 GitHub stars~11k tokensUpdated 26 days ago
    SecurityAuto-check: notes
  • Implementing Aes Encryption For Data At REST

    mukul975/Anthropic-Cybersecurity-Skills

    Guides implementing AES-256 encryption in GCM mode (FIPS 197) for files and data stores at rest, covering key derivation, IV/nonce management, and authenticated encryption.

    34k GitHub stars~1.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Ssl Tls Inspection Configuration

    mukul975/Anthropic-Cybersecurity-Skills

    Configure SSL/TLS break-and-inspect on next-generation firewalls and forward proxies to decrypt, inspect, and re-encrypt HTTPS traffic for malware and exfiltration detection, including deploying…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Security Review Spec

    warpdotdev/oz-for-oss

    Audit a product or tech spec pull request diff for high-level security concerns (threat surface, authentication and authorization model, trust boundaries, sensitive data handling, secrets and key…

    312 GitHub starsUsed in 1 repo~2.6k tokens
    SecurityAuto-check passed
  • Security

    OpenHands/extensions

    Security best practices for secure coding, authentication, authorization, and data protection.

    163 GitHub stars~342 tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    SecurityAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated yesterday
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Deepgram Security Basics

What does Deepgram Security Basics do?

Apply Deepgram security best practices for API key management and data protection. Deepgram Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Apply Deepgram security best practices for API key management and data protection.

When should I use Deepgram Security Basics?

Deepgram Security Basics fits situations like: securing Deepgram integrations; implementing key rotation; auditing security configurations.

How do I install Deepgram Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill deepgram-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/deepgram-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/deepgram-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Deepgram Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill deepgram-security-basics -a codex`. Or copy the skill folder (skills/.curated/deepgram-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/deepgram-security-basics in your project. Codex loads it when a task matches its description.

Can I use Deepgram Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill deepgram-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deepgram-security-basics, .gemini/skills/deepgram-security-basics, .github/skills/deepgram-security-basics and .opencode/skills/deepgram-security-basics in your project.

What does Deepgram Security Basics need to run?

Going by SKILL.md and its folder, Deepgram Security Basics needs credentials named DEEPGRAM_API_KEY, DEEPGRAM_ADMIN_KEY, DEEPGRAM_STT_KEY and DEEPGRAM_TTS_KEY. Our summary lists: A credential in DEEPGRAM_STT_KEY; A credential in DEEPGRAM_TTS_KEY. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Bash(curl:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Deepgram Security Basics access the network?

SKILL.md names 1 domain. As links in the text: developers.deepgram.com. This is read from the text; nothing was executed.

Is Deepgram Security Basics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Deepgram Security Basics use?

Deepgram Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deepgram Security Basics use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Deepgram Security Basics?

Skills that share tags, products or a category with Deepgram Security Basics: Security Review (valory-xyz/open-autonomy, 129 stars), Implementing Aes Encryption For Data At REST (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Ssl Tls Inspection Configuration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Security Review Spec (warpdotdev/oz-for-oss, 312 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deepgram Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.