Agent skill

Fathom Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Secure Fathom API keys and handle meeting data privacy. An agent skill from jeremylongshore/tons-of-skills-marketplace.

MITAuto-check passedLegal & Compliance

Install Fathom Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill fathom-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace fathom-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/fathom-security-basics .claude/skills/fathom-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fathom-security-basics
GitHub stars
2.8k
Token cost
~1.3k tokens
SKILL.md length
327 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Secure Fathom API keys and handle meeting data privacy. An agent skill from jeremylongshore/tons-of-skills-marketplace.

  • Works in 4 steps: Apply least-privilege roles and approved… → Keep credentials in the secret manager… → Validate integrations and sharing… → …
  • With phrases like fathom security
  • SKILL.md covers Prerequisites, Instructions, Output and Examples, plus 9 more sections
  • Reaches api.fathom.video; needs FATHOM_API_KEY and FATHOM_WEBHOOK_SECRET

What it does

Fathom Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Secure Fathom API keys and handle meeting data privacy. Trigger with phrases like "fathom security", "fathom api key safety", "fathom privacy".

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Privacy and GDPR and Webhooks. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • With phrases like fathom security
  • Fathom api key safety

Example prompts

  • “fathom security”
  • “fathom api key safety”
  • “fathom privacy”
  • “/fathom-security-basics”

Requirements

  • A credential in FATHOM_API_KEY
  • A credential in FATHOM_WEBHOOK_SECRET
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Apply least-privilege roles and approved recording/transcript access settings.
  2. Keep credentials in the secret manager and meeting content out of logs and test fixtures.
  3. Validate integrations and sharing controls with synthetic records before broad rollout.
  4. Revoke access and follow the incident process on suspected exposure.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.fathom.video

    Also links to:

    • fathom.video
    • owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • FATHOM_API_KEY
    • FATHOM_WEBHOOK_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Fathom Security Basics loads about 1.3k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 327 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 327 words, ~1,300 tokens.

Download SKILL.mdSave it as .claude/skills/fathom-security-basics/SKILL.md (or your agent's skills folder).
name
fathom-security-basics
description
Secure Fathom API keys and handle meeting data privacy. Trigger with phrases like "fathom security", "fathom api key safety", "fathom privacy".
allowed-tools
Read, Write, Edit, Grep
compatibility
Designed for Claude Code
version
1.6.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, meeting-intelligence, ai-notes, fathom

Fathom Security Basics

Prerequisites

  • A current recording/data classification, consent policy, scoped identity/secrets, and incident owner.

Instructions

  1. Apply least-privilege roles and approved recording/transcript access settings.
  2. Keep credentials in the secret manager and meeting content out of logs and test fixtures.
  3. Validate integrations and sharing controls with synthetic records before broad rollout.
  4. Revoke access and follow the incident process on suspected exposure.

Output

  • A controlled Fathom deployment with data/consent safeguards, scoped credentials, access review, and incident path.

Examples

Verify a development role can access only its synthetic meeting record and cannot retrieve production content, then record the redacted result and review date. If a token, recording, transcript, or participant data is exposed, contain/revoke first and follow the data incident process.

Overview

Fathom records and transcribes meetings, producing transcripts and action items that contain participant PII (names, emails, spoken content), confidential business decisions, and potentially sensitive negotiations. API keys are per-user and grant access to all meetings the user recorded or that were shared to their team. Protect recording consent workflows, transcript storage, and any analytics pipeline touching meeting content.

API Key Management

typescript
function createFathomClient(): { apiKey: string; baseUrl: string } {
  const apiKey = process.env.FATHOM_API_KEY;
  if (!apiKey) {
    throw new Error("Missing FATHOM_API_KEY — store in secrets manager, never in code");
  }
  // Fathom keys are per-user — never share across team members
  console.log("Fathom client initialized (key hash:", apiKey.slice(-4), ")");
  return { apiKey, baseUrl: "https://api.fathom.video/v1" };
}

Webhook Signature Verification

typescript
import crypto from "crypto";
import { Request, Response, NextFunction } from "express";

function verifyFathomWebhook(req: Request, res: Response, next: NextFunction): void {
  const signature = req.headers["x-fathom-signature"] as string;
  const secret = process.env.FATHOM_WEBHOOK_SECRET!;
  const expected = crypto.createHmac("sha256", secret).update(req.body).digest("hex");
  if (!signature || !crypto.timingSafeEqual(Buffer.from(signature), Buffer.from(expected))) {
    res.status(401).send("Invalid signature");
    return;
  }
  next();
}

Input Validation

typescript
import { z } from "zod";

const MeetingQuerySchema = z.object({
  meeting_id: z.string().uuid(),
  include_transcript: z.boolean().default(false),
  date_from: z.string().regex(/^\d{4}-\d{2}-\d{2}$/).optional(),
  date_to: z.string().regex(/^\d{4}-\d{2}-\d{2}$/).optional(),
  participant_email: z.string().email().optional(),
});

function validateMeetingQuery(data: unknown) {
  return MeetingQuerySchema.parse(data);
}

Data Protection

typescript
const FATHOM_PII_FIELDS = ["participant_email", "participant_name", "phone_number", "transcript_text"];

function redactFathomLog(record: Record<string, unknown>): Record<string, unknown> {
  const redacted = { ...record };
  for (const field of FATHOM_PII_FIELDS) {
    if (field in redacted) redacted[field] = "[REDACTED]";
  }
  // Also scrub emails from transcript snippets
  if (typeof redacted.summary === "string") {
    redacted.summary = (redacted.summary as string).replace(/[\w.+-]+@[\w-]+\.[\w.-]+/g, "[REDACTED_EMAIL]");
  }
  return redacted;
}

Security Checklist

  • API key stored in secrets manager, never in code
  • Meeting recordings and transcripts encrypted at rest
  • PII redacted in non-production environments
  • Webhook endpoints use HTTPS with signature verification
  • Access logs track per-user API key usage
  • Recording consent verified before processing transcripts
  • Transcript data retention policy enforced
  • Action items containing confidential terms scrubbed before export

Error Handling

VulnerabilityRiskMitigation
Leaked API keyAccess to all user meetings and transcriptsSecrets manager + key regeneration
Unredacted transcripts in logsParticipant PII exposureField-level redaction pipeline
Missing recording consentLegal liability under two-party consent lawsConsent verification before processing
Unencrypted transcript storageBulk meeting data breachEncryption at rest + access controls
Overly broad meeting sharingConfidential content exposed to wrong teamsPer-meeting permission scoping

Resources

Next Steps

See fathom-prod-checklist.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/.curated/fathom-security-basics of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Fathom Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fathom Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fathom Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMIT
Privacy Pagamenticcplugins/awesome-claude-code-plugins970—~845Automated safety check: PassApache-2.0
Email Best Practicesviclafouch/meme-studio1107 repos~787Automated safety check: PassNone
Eu Data Act Oliver Schmidt Prietzlawve-ai/awesome-legal-skills847—~3.9kAutomated safety check: PassAGPL-3.0
Healthcare Phi Complianceaffaan-m/ECC276k1 repos~1.4kAutomated safety check: PassMIT
Security Compliancesangrokjung/claude-forge8522 repos~7.2kAutomated safety check: PassMIT

Similar skills

  • Privacy Pagamenti

    ccplugins/awesome-claude-code-plugins

    Protegge dati di pagamento e abbonamenti quando un sito/app gestisce checkout, carte, subscription o fatturazione.

    970 GitHub stars~845 tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Email Best Practices

    viclafouch/meme-studio

    A skill your agent uses when building email features, emails going to spam, high bounce rates, setting up SPF/DKIM/DMARC authentication, implementing email capture, ensuring compliance (CAN-SPAM…

    110 GitHub starsUsed in 7 repos~787 tokens
    Backend & APIsAuto-check passed
  • Eu Data Act Oliver Schmidt Prietz

    lawve-ai/awesome-legal-skills

    Practitioner skill for advising on EU Regulation 2023/2854 (Data Act).

    847 GitHub stars~3.9k tokensUpdated 8 days ago
    Legal & ComplianceAuto-check passed
  • Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…

    276k GitHub starsUsed in 1 repo~1.4k tokens
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    852 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Incident Reporting Navigator

    davila7/claude-code-templates

    A skill your agent uses when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where, and by when?" Screens one incident across the EU…

    33k GitHub starsUsed in 1 repo~4.7k tokens
    Legal & ComplianceAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Fathom Security Basics

What does Fathom Security Basics do?

Secure Fathom API keys and handle meeting data privacy. An agent skill from jeremylongshore/tons-of-skills-marketplace. Fathom Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Secure Fathom API keys and handle meeting data privacy.

When should I use Fathom Security Basics?

Fathom Security Basics fits situations like: with phrases like fathom security; fathom api key safety.

How do I install Fathom Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill fathom-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/fathom-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/fathom-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Fathom Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill fathom-security-basics -a codex`. Or copy the skill folder (skills/.curated/fathom-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/fathom-security-basics in your project. Codex loads it when a task matches its description.

Can I use Fathom Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill fathom-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fathom-security-basics, .gemini/skills/fathom-security-basics, .github/skills/fathom-security-basics and .opencode/skills/fathom-security-basics in your project.

What does Fathom Security Basics need to run?

Going by SKILL.md and its folder, Fathom Security Basics needs credentials named FATHOM_API_KEY and FATHOM_WEBHOOK_SECRET. Our summary lists: A credential in FATHOM_API_KEY; A credential in FATHOM_WEBHOOK_SECRET. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Fathom Security Basics access the network?

SKILL.md names 3 domains. In commands or code: api.fathom.video; the agent is likely to contact it when it follows the instructions. As links in the text: fathom.video and owasp.org. This is read from the text; nothing was executed.

Is Fathom Security Basics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fathom Security Basics use?

Fathom Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fathom Security Basics use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fathom Security Basics?

Skills that share tags, products or a category with Fathom Security Basics: Privacy Pagamenti (ccplugins/awesome-claude-code-plugins, 970 stars), Email Best Practices (viclafouch/meme-studio, 110 stars), Eu Data Act Oliver Schmidt Prietz (lawve-ai/awesome-legal-skills, 847 stars) and Healthcare Phi Compliance (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fathom Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.