Review Hog Perspective Contracts Security
PostHog/posthog
The Contracts & Security review perspective for PostHog Review.
Apply Framer security best practices for secrets and access control.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill framer-security-basics -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace framer-security-basics --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/framer-security-basics .claude/skills/framer-security-basics && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "framer-security-basics" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/framer-security-basics into .claude/skills/framer-security-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "framer-security-basics", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/framer-security-basicsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill framer-security-basics -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace framer-security-basics --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/framer-security-basics .agents/skills/framer-security-basics && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "framer-security-basics" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/framer-security-basics into .agents/skills/framer-security-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "framer-security-basics", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill framer-security-basics -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace framer-security-basics --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/framer-security-basics .cursor/skills/framer-security-basics && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "framer-security-basics" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/framer-security-basics into .cursor/skills/framer-security-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "framer-security-basics", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/framer-security-basics--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill framer-security-basics -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace framer-security-basics --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/framer-security-basics .gemini/skills/framer-security-basics && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "framer-security-basics" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/framer-security-basics into .gemini/skills/framer-security-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "framer-security-basics", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace framer-security-basicsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill framer-security-basics -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/framer-security-basics .github/skills/framer-security-basics && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "framer-security-basics" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/framer-security-basics into .github/skills/framer-security-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "framer-security-basics", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill framer-security-basics -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace framer-security-basics --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/framer-security-basics .opencode/skills/framer-security-basics && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "framer-security-basics" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/framer-security-basics into .opencode/skills/framer-security-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "framer-security-basics", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
framer-security-basicsApply Framer security best practices for secrets and access control.
Framer Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Apply Framer security best practices for secrets and access control. Use when securing API keys, implementing least privilege access, or auditing Framer security configuration. Trigger with phrases like "framer security", "framer secrets", "secure framer", "framer API key security".
Its SKILL.md is about 770 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code
It sits in Security, covering Authorization and RBAC and Security review. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteGrepFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
nodeFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
framer.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
FRAMER_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Framer Security Basics loads about 767 tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 199 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
# .env (never commit).env.env.local- [ ] `.env` in `.gitignore`Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 199 words, ~767 tokens.
.claude/skills/framer-security-basics/SKILL.md (or your agent's skills folder).A security owner, least-privilege access policy, secret-manager references, domain/DNS ownership, and synthetic test project.
Maintain a security receipt with identity scope, control result, access-review date, owner, and redacted incident state. Do not include keys, form submissions, or private content.
Deny unexpected permissions or publishing destinations, revoke access on suspected exposure, and route incidents through the designated owner.
Use a staging site to verify a temporary collaborator cannot publish to production, remove access, and record only the control outcome and opaque project reference.
Security best practices for Framer API keys, plugin development, and Server API access.
| Credential | Scope | Where to Store |
|---|---|---|
Server API Key (framer_sk_*) | Per-site | Secrets vault |
| Site ID | Per-site | Can be in config |
| Plugin auth tokens | Per-user session | Never persist |
# .env (never commit)
FRAMER_API_KEY=framer_sk_abc123...
FRAMER_SITE_ID=abc123
# .gitignore
.env
.env.local// Plugins run in Framer's iframe sandbox — limited browser APIs
// Never store secrets in plugin code (it's client-side)
// Fetch external data through your own API proxy
const data = await fetch('https://your-api.com/framer-data', {
headers: { 'Authorization': `Bearer ${sessionToken}` },
});# 1. Generate new key in Framer site settings
# 2. Update in secrets vault
# 3. Test connection
node -e "
const { framer } = require('framer-api');
framer.connect({ apiKey: process.env.FRAMER_API_KEY, siteId: process.env.FRAMER_SITE_ID })
.then(() => console.log('OK'))
.catch(e => console.error('FAIL', e.message));
"
# 4. Revoke old key in site settings.env in .gitignoreframer_sk_* leaksFor production deployment, see framer-prod-checklist.
© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/.curated/framer-security-basics of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Framer Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Framer Security Basics this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~767 | Automated safety check: Notes | MIT | |
| Review Hog Perspective Contracts SecurityPostHog/posthog | 40k | — | ~1k | Automated safety check: Pass | Custom licence | |
| Review Securityhashgraph-online/awesome-codex-plugins | 1.3k | — | ~601 | Automated safety check: Pass | Apache-2.0 | |
| Security Review ChecklistZeroDeng01/sublinkPro | 1.7k | — | ~2.3k | Automated safety check: Pass | MIT | |
| Absolute Auditmaddhruv/absolute | 219 | 1 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Warden Security ReviewUsefulSoftwareCo/executor | 4.1k | — | ~1.3k | Automated safety check: Pass | MIT |
PostHog/posthog
The Contracts & Security review perspective for PostHog Review.
hashgraph-online/awesome-codex-plugins
Review application and infrastructure changes for exploitable security risks by tracing assets, trust boundaries, attacker-controlled input, authorization, sensitive data, and dangerous sinks.
ZeroDeng01/sublinkPro
Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.
maddhruv/absolute
Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without…
UsefulSoftwareCo/executor
Run Warden security scans in this repo using Sentry's warden-skills.
langfuse/langfuse
Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Categories
Apply Framer security best practices for secrets and access control. Framer Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Apply Framer security best practices for secrets and access control.
Framer Security Basics fits situations like: securing API keys; implementing least privilege access; auditing Framer security configuration; with phrases like framer security.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill framer-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/framer-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/framer-security-basics in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill framer-security-basics -a codex`. Or copy the skill folder (skills/.curated/framer-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/framer-security-basics in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill framer-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/framer-security-basics, .gemini/skills/framer-security-basics, .github/skills/framer-security-basics and .opencode/skills/framer-security-basics in your project.
Going by SKILL.md and its folder, Framer Security Basics needs the command-line tools its instructions call (node) and credentials named FRAMER_API_KEY. Our summary lists: A credential in FRAMER_API_KEY. Its frontmatter pre-approves these tools: Read, Write, Grep. Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md names 1 domain. As links in the text: framer.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Framer Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 767 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Framer Security Basics: Review Hog Perspective Contracts Security (PostHog/posthog, 40k stars), Review Security (hashgraph-online/awesome-codex-plugins, 1.3k stars), Security Review Checklist (ZeroDeng01/sublinkPro, 1.7k stars) and Absolute Audit (maddhruv/absolute, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.