Agent skill

Elevenlabs Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Apply ElevenLabs security best practices for API keys, webhook HMAC validation, and voice data protection.

MITAuto-check: notesBackend & APIs

Install Elevenlabs Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill elevenlabs-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace elevenlabs-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/elevenlabs-security-basics .claude/skills/elevenlabs-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
elevenlabs-security-basics
GitHub stars
2.8k
Token cost
~1.5k tokens
SKILL.md length
573 words
Files
3 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Apply ElevenLabs security best practices for API keys, webhook HMAC validation, and voice data protection.

  • Works in 6 steps: API Key Management → Environment-Specific Keys → Webhook HMAC Signature Verification → …
  • Securing API keys
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 6 more sections
  • Needs ELEVENLABS_API_KEY

What it does

Elevenlabs Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Apply ElevenLabs security best practices for API keys, webhook HMAC validation, and voice data protection. Use when securing API keys, validating webhook signatures, or auditing ElevenLabs security configuration. Trigger with "elevenlabs security", "elevenlabs secrets", "secure elevenlabs", "elevenlabs API key security", "elevenlabs webhook signature", "elevenlabs HMAC".

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/examples.md` and `references/implementation.md`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Text to speech and voice, Webhooks and Privacy and GDPR. It works with ElevenLabs. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Securing API keys
  • Validating webhook signatures
  • Auditing ElevenLabs security configuration
  • With elevenlabs security

Example prompts

  • “elevenlabs security”
  • “elevenlabs secrets”
  • “secure elevenlabs”
  • “/elevenlabs-security-basics”

Requirements

  • A credential in ELEVENLABS_API_KEY
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Grep

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. API Key Management
  2. Environment-Specific Keys
  3. Webhook HMAC Signature Verification
  4. Express Webhook Endpoint with Verification
  5. API Key Rotation Procedure
  6. Voice Data Protection

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • elevenlabs.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ELEVENLABS_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Elevenlabs Security Basics loads about 1.5k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 573 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:50
    # .env (NEVER commit to git)
  • NoteMentions a .env fileSKILL.md:54
    .env
  • NoteMentions a .env fileSKILL.md:55
    .env.local
  • NoteMentions a .env fileSKILL.md:56
    .env.*.local
  • NoteMentions a .env fileSKILL.md:105
    red only in environment variables, with `.env` gitignored and a
  • NoteMentions a .env fileSKILL.md:116
    - [ ] `.env` files in `.gitignore`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 573 words, ~1,517 tokens.

Download SKILL.mdSave it as .claude/skills/elevenlabs-security-basics/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
elevenlabs-security-basics
description
Apply ElevenLabs security best practices for API keys, webhook HMAC validation, and voice data protection. Use when securing API keys, validating webhook signatures, or auditing ElevenLabs security configuration. Trigger with "elevenlabs security", "elevenlabs secrets", "secure elevenlabs", "elevenlabs API key security", "elevenlabs webhook signature", "elevenlabs HMAC".
allowed-tools
Read, Write, Grep
compatibility
Designed for Claude Code
version
1.6.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, voice, ai, elevenlabs, security, webhooks

ElevenLabs Security Basics

Overview

Security best practices for ElevenLabs API key management, webhook HMAC signature verification, and protecting cloned voice data. ElevenLabs uses a single API key (xi-api-key) and HMAC webhook authentication.

This SKILL.md carries the workflow at a high level with the essential skeletons. Full production code for each step lives in references/implementation.md, and end-to-end scenarios live in references/examples.md.

Prerequisites

  • ElevenLabs SDK installed
  • Understanding of environment variables
  • Access to ElevenLabs dashboard (Settings > API Keys)

Instructions

Step 1: API Key Management

Keep keys out of source, and add a hook that blocks accidental commits:

bash
# .env (NEVER commit to git)
ELEVENLABS_API_KEY=sk_your_key_here

# .gitignore — MUST include these
.env
.env.local
.env.*.local
bash
#!/bin/bash
# .git/hooks/pre-commit — reject staged ElevenLabs keys
if git diff --cached | grep -qE 'sk_[a-zA-Z0-9]{20,}'; then
  echo "ERROR: ElevenLabs API key detected in staged changes!"
  echo "Remove the key and use environment variables instead."
  exit 1
fi
Step 2: Environment-Specific Keys

Load the key at startup, fail fast when it is missing, and warn if a production key leaks into development. Full getSecurityConfig() implementation: references/implementation.md.

Step 3: Webhook HMAC Signature Verification

ElevenLabs webhooks carry an ElevenLabs-Signature header formatted as t=TIMESTAMP,v1=SIGNATURE. Verify it with HMAC-SHA256, reject timestamps older than 5 minutes (replay protection), and use a timing-safe comparison. Full verifyWebhookSignature() implementation: references/implementation.md.

Step 4: Express Webhook Endpoint with Verification

Verify against the raw request body, respond 200 fast, then process asynchronously so you never trip the webhook timeout. Full endpoint: references/implementation.md.

Step 5: API Key Rotation Procedure

Generate the new key, validate it before cutover, push to every environment, verify production, then revoke the old key — zero downtime. Full runbook: references/implementation.md.

Step 6: Voice Data Protection

Cloned voices are biometric PII: restrict who can clone, audit-log every operation, and require documented consent. Full policy and audit logger: references/implementation.md.

Output

Applying this skill produces a hardened ElevenLabs integration:

  • API keys stored only in environment variables, with .env gitignored and a pre-commit hook that blocks the sk_ key pattern.
  • A verifyWebhookSignature() helper and Express endpoint that reject invalid signatures (HTTP 401) and replayed requests (timestamp > 5 minutes).
  • A documented, zero-downtime key rotation runbook.
  • Structured audit logs (elevenlabs.voice.audit) for every voice clone, delete, and use, plus a completed Security Checklist below.
Show full SKILL.md (259 more words)Show less

Security Checklist

  • API keys in environment variables (never in source code)
  • .env files in .gitignore
  • Different API keys for dev/staging/prod
  • Pre-commit hook scanning for key patterns (sk_)
  • Webhook signatures verified with HMAC-SHA256
  • Replay protection on webhooks (5-minute timestamp check)
  • Webhook failures monitored (auto-disabled after 10 consecutive failures)
  • Voice cloning operations audit-logged
  • Cloned voice consent documented
  • API key rotation scheduled quarterly

Webhook Failure Policy

ElevenLabs auto-disables webhooks after:

  • 10+ consecutive delivery failures, AND
  • Last successful delivery was 7+ days ago (or never delivered)

Always return HTTP 200 quickly from your webhook handler.

Error Handling

Security IssueDetectionMitigation
Exposed API keyGit scanning, CI checkRotate immediately, revoke old key
Invalid webhook signatureverifyWebhookSignature() returns falseLog and reject (HTTP 401)
Replay attackTimestamp > 5 minutes oldReject with timestamp check
Unauthorized voice cloningAudit logsRestrict clone permissions

Examples

Worked, end-to-end scenarios live in references/examples.md:

  • Block a key commit before it happens — the pre-commit hook aborts a commit containing sk_....
  • Reject a replayed webhook — a correct HMAC still fails on a 6-minute-old timestamp.
  • Rotate a leaked production key with zero downtime — validate the new key, cut over, then revoke.
  • Audit a voice-clone operation — structured JSON proving who cloned a voice and whether consent was on file.

Resources

Next Steps

Once these basics are in place, harden the wider deployment: apply the elevenlabs-prod-checklist skill for production readiness, schedule the quarterly key rotation from Step 5, and wire the voice audit logs into your central logging or SIEM so cloning activity is reviewable.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/.curated/elevenlabs-security-basics of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/examples.md
  • references/implementation.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Elevenlabs Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Elevenlabs Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Elevenlabs Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.5kAutomated safety check: NotesMIT
Integrate Whatsapp Callinggokapso/agent-skills177—~2.1kAutomated safety check: PassNone
Elevenlabs Agentsjezweb/claude-skills1.1k—~3.3kAutomated safety check: PassMIT
AI SDK Developmenttrypostit/trypost6921 repos~3.5kAutomated safety check: PassMIT
Email Best Practicesviclafouch/meme-studio1107 repos~787Automated safety check: PassNone
Speech Engineelevenlabs/skills482—~2.5kAutomated safety check: WarnMIT

Similar skills

  • Integrate Whatsapp Calling

    gokapso/agent-skills

    Connect voice agents to WhatsApp Calling through Kapso. An agent skill from gokapso/agent-skills.

    177 GitHub stars~2.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Elevenlabs Agents

    jezweb/claude-skills

    Build conversational AI voice agents on the ElevenLabs platform.

    1.1k GitHub stars~3.3k tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed
  • AI SDK Development

    trypostit/trypost

    TRIGGER when working with ai-sdk which is Laravel official first-party AI SDK.

    692 GitHub starsUsed in 1 repo~3.5k tokens
    AI & LLM EngineeringAuto-check passed
  • Email Best Practices

    viclafouch/meme-studio

    A skill your agent uses when building email features, emails going to spam, high bounce rates, setting up SPF/DKIM/DMARC authentication, implementing email capture, ensuring compliance (CAN-SPAM…

    110 GitHub starsUsed in 7 repos~787 tokens
    Backend & APIsAuto-check passed
  • Speech Engine

    elevenlabs/skills

    Add real-time voice conversations to a custom agent runtime with ElevenLabs Speech Engine.

    482 GitHub stars~2.5k tokensUpdated 2 days ago
    Media & CreativeAuto-check: warnings
  • Agents

    elevenlabs/skills

    Build voice AI agents with ElevenLabs. An agent skill from elevenlabs/skills.

    482 GitHub stars~6.5k tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Elevenlabs Security Basics

What does Elevenlabs Security Basics do?

Apply ElevenLabs security best practices for API keys, webhook HMAC validation, and voice data protection. Elevenlabs Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Apply ElevenLabs security best practices for API keys, webhook HMAC validation, and voice data protection.

When should I use Elevenlabs Security Basics?

Elevenlabs Security Basics fits situations like: securing API keys; validating webhook signatures; auditing ElevenLabs security configuration; with elevenlabs security.

How do I install Elevenlabs Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill elevenlabs-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/elevenlabs-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/elevenlabs-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Elevenlabs Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill elevenlabs-security-basics -a codex`. Or copy the skill folder (skills/.curated/elevenlabs-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/elevenlabs-security-basics in your project. Codex loads it when a task matches its description.

Can I use Elevenlabs Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill elevenlabs-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elevenlabs-security-basics, .gemini/skills/elevenlabs-security-basics, .github/skills/elevenlabs-security-basics and .opencode/skills/elevenlabs-security-basics in your project.

What does Elevenlabs Security Basics need to run?

Going by SKILL.md and its folder, Elevenlabs Security Basics needs credentials named ELEVENLABS_API_KEY. Our summary lists: A credential in ELEVENLABS_API_KEY. Its frontmatter pre-approves these tools: Read, Write, Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Elevenlabs Security Basics access the network?

SKILL.md names 1 domain. As links in the text: elevenlabs.io. This is read from the text; nothing was executed.

Is Elevenlabs Security Basics safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Elevenlabs Security Basics use?

Elevenlabs Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Elevenlabs Security Basics use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Elevenlabs Security Basics?

Skills that share tags, products or a category with Elevenlabs Security Basics: Integrate Whatsapp Calling (gokapso/agent-skills, 177 stars), Elevenlabs Agents (jezweb/claude-skills, 1.1k stars), AI SDK Development (trypostit/trypost, 692 stars) and Email Best Practices (viclafouch/meme-studio, 110 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Elevenlabs Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.