Agent skill

Framer Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Apply Framer security best practices for secrets and access control.

MITAuto-check: notesSecurity

Install Framer Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill framer-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace framer-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/framer-security-basics .claude/skills/framer-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
framer-security-basics
GitHub stars
2.8k
Token cost
~767 tokens
SKILL.md length
199 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Apply Framer security best practices for secrets and access control.

  • Works in 4 steps: Credential Management → Plugin Security → Server API Key Rotation → …
  • Securing API keys
  • SKILL.md covers Prerequisites, Output, Error Handling and Examples, plus 4 more sections
  • Calls node; needs FRAMER_API_KEY

What it does

Framer Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Apply Framer security best practices for secrets and access control. Use when securing API keys, implementing least privilege access, or auditing Framer security configuration. Trigger with phrases like "framer security", "framer secrets", "secure framer", "framer API key security".

Its SKILL.md is about 770 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code

It sits in Security, covering Authorization and RBAC and Security review. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Securing API keys
  • Implementing least privilege access
  • Auditing Framer security configuration
  • With phrases like framer security

Example prompts

  • “framer security”
  • “framer secrets”
  • “secure framer”
  • “/framer-security-basics”

Requirements

  • A credential in FRAMER_API_KEY
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Grep

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Credential Management
  2. Plugin Security
  3. Server API Key Rotation
  4. Security Checklist

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • framer.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • FRAMER_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Framer Security Basics loads about 767 tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 199 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~767

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:56
    # .env (never commit)
  • NoteMentions a .env fileSKILL.md:61
    .env
  • NoteMentions a .env fileSKILL.md:62
    .env.local
  • NoteMentions a .env fileSKILL.md:95
    - [ ] `.env` in `.gitignore`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 199 words, ~767 tokens.

Download SKILL.mdSave it as .claude/skills/framer-security-basics/SKILL.md (or your agent's skills folder).
name
framer-security-basics
description
Apply Framer security best practices for secrets and access control. Use when securing API keys, implementing least privilege access, or auditing Framer security configuration. Trigger with phrases like "framer security", "framer secrets", "secure framer", "framer API key security".
allowed-tools
Read, Write, Grep
compatibility
Designed for Claude Code
version
1.5.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, framer

Framer Security Basics

Prerequisites

A security owner, least-privilege access policy, secret-manager references, domain/DNS ownership, and synthetic test project.

Output

Maintain a security receipt with identity scope, control result, access-review date, owner, and redacted incident state. Do not include keys, form submissions, or private content.

Error Handling

Deny unexpected permissions or publishing destinations, revoke access on suspected exposure, and route incidents through the designated owner.

Examples

Use a staging site to verify a temporary collaborator cannot publish to production, remove access, and record only the control outcome and opaque project reference.

Overview

Security best practices for Framer API keys, plugin development, and Server API access.

Instructions

Step 1: Credential Management
CredentialScopeWhere to Store
Server API Key (framer_sk_*)Per-siteSecrets vault
Site IDPer-siteCan be in config
Plugin auth tokensPer-user sessionNever persist
bash
# .env (never commit)
FRAMER_API_KEY=framer_sk_abc123...
FRAMER_SITE_ID=abc123

# .gitignore
.env
.env.local
Step 2: Plugin Security
tsx
// Plugins run in Framer's iframe sandbox — limited browser APIs
// Never store secrets in plugin code (it's client-side)

// Fetch external data through your own API proxy
const data = await fetch('https://your-api.com/framer-data', {
  headers: { 'Authorization': `Bearer ${sessionToken}` },
});
Step 3: Server API Key Rotation
bash
# 1. Generate new key in Framer site settings
# 2. Update in secrets vault
# 3. Test connection
node -e "
  const { framer } = require('framer-api');
  framer.connect({ apiKey: process.env.FRAMER_API_KEY, siteId: process.env.FRAMER_SITE_ID })
    .then(() => console.log('OK'))
    .catch(e => console.error('FAIL', e.message));
"
# 4. Revoke old key in site settings
Step 4: Security Checklist
  • API keys in environment variables, never in code
  • .env in .gitignore
  • Plugin never stores or exposes API keys
  • Server API accessed only from backend, never client
  • Pre-commit hook scans for framer_sk_* leaks
  • HTTPS-only for all API communication

Resources

Next Steps

For production deployment, see framer-prod-checklist.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/.curated/framer-security-basics of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Framer Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Framer Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Framer Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~767Automated safety check: NotesMIT
Review Hog Perspective Contracts SecurityPostHog/posthog40k—~1kAutomated safety check: PassCustom licence
Review Securityhashgraph-online/awesome-codex-plugins1.3k—~601Automated safety check: PassApache-2.0
Security Review ChecklistZeroDeng01/sublinkPro1.7k—~2.3kAutomated safety check: PassMIT
Absolute Auditmaddhruv/absolute2191 repos~1.2kAutomated safety check: PassMIT
Warden Security ReviewUsefulSoftwareCo/executor4.1k—~1.3kAutomated safety check: PassMIT

Similar skills

  • Review Security

    hashgraph-online/awesome-codex-plugins

    Review application and infrastructure changes for exploitable security risks by tracing assets, trust boundaries, attacker-controlled input, authorization, sensitive data, and dangerous sinks.

    1.3k GitHub stars~601 tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Review Checklist

    ZeroDeng01/sublinkPro

    Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

    1.7k GitHub stars~2.3k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Absolute Audit

    maddhruv/absolute

    Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without…

    219 GitHub starsUsed in 1 repo~1.2k tokens
    SecurityAuto-check passed
  • Warden Security Review

    UsefulSoftwareCo/executor

    Run Warden security scans in this repo using Sentry's warden-skills.

    4.1k GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check passed
  • Security Review

    langfuse/langfuse

    Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.

    36k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Framer Security Basics

What does Framer Security Basics do?

Apply Framer security best practices for secrets and access control. Framer Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Apply Framer security best practices for secrets and access control.

When should I use Framer Security Basics?

Framer Security Basics fits situations like: securing API keys; implementing least privilege access; auditing Framer security configuration; with phrases like framer security.

How do I install Framer Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill framer-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/framer-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/framer-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Framer Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill framer-security-basics -a codex`. Or copy the skill folder (skills/.curated/framer-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/framer-security-basics in your project. Codex loads it when a task matches its description.

Can I use Framer Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill framer-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/framer-security-basics, .gemini/skills/framer-security-basics, .github/skills/framer-security-basics and .opencode/skills/framer-security-basics in your project.

What does Framer Security Basics need to run?

Going by SKILL.md and its folder, Framer Security Basics needs the command-line tools its instructions call (node) and credentials named FRAMER_API_KEY. Our summary lists: A credential in FRAMER_API_KEY. Its frontmatter pre-approves these tools: Read, Write, Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Framer Security Basics access the network?

SKILL.md names 1 domain. As links in the text: framer.com. This is read from the text; nothing was executed.

Is Framer Security Basics safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Framer Security Basics use?

Framer Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Framer Security Basics use?

About 767 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Framer Security Basics?

Skills that share tags, products or a category with Framer Security Basics: Review Hog Perspective Contracts Security (PostHog/posthog, 40k stars), Review Security (hashgraph-online/awesome-codex-plugins, 1.3k stars), Security Review Checklist (ZeroDeng01/sublinkPro, 1.7k stars) and Absolute Audit (maddhruv/absolute, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Framer Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.