Agent skill

Glean Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Token security: Indexing tokens have write access -- never expose in frontend.

MITAuto-check passedBackend & APIs

Install Glean Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill glean-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace glean-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/glean-security-basics .claude/skills/glean-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
glean-security-basics
GitHub stars
2.8k
Token cost
~1.5k tokens
SKILL.md length
401 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Token security: Indexing tokens have write access -- never expose in frontend.

  • Works in 5 steps: Scope credentials by environment and… → Validate document schema, size, origin,… → Verify webhook authenticity before… → …
  • Backend & APIs work in your project
  • SKILL.md covers Overview, API Key Management, Webhook Signature Verification and Input Validation, plus 9 more sections
  • Needs GLEAN_INDEXING_TOKEN and GLEAN_CLIENT_TOKEN

What it does

Glean Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Token security: Indexing tokens have write access -- never expose in frontend. Trigger: "glean security basics", "security-basics".

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code

It sits in Backend & APIs. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “glean security basics”
  • “security-basics”
  • “/glean-security-basics”

Requirements

  • A credential in GLEAN_INDEXING_TOKEN
  • A credential in GLEAN_CLIENT_TOKEN
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(npm:*), Bash(curl:*), Grep

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Scope credentials by environment and datasource, inject them from the secret manager, and deny unknown scope or destination.
  2. Validate document schema, size, origin, and ACL before indexing; quarantine failures with opaque correlation IDs.
  3. Verify webhook authenticity before parsing, validate comparable lengths before constant-time comparison, and reject replayed or stale…
  4. Run synthetic allow and deny probes after ACL or identity changes, logging policy revisions and aggregates rather than content.
  5. Rotate or revoke compromised credentials, disable a connector if integrity is uncertain, and preserve redacted incident evidence.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(npm:*)
    • Bash(curl:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.glean.com
    • owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GLEAN_INDEXING_TOKEN
    • GLEAN_CLIENT_TOKEN
    • GLEAN_WEBHOOK_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Glean Security Basics loads about 1.5k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 401 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 401 words, ~1,485 tokens.

Download SKILL.mdSave it as .claude/skills/glean-security-basics/SKILL.md (or your agent's skills folder).
name
glean-security-basics
description
Token security: Indexing tokens have write access -- never expose in frontend. Trigger: "glean security basics", "security-basics".
allowed-tools
Read, Write, Edit, Bash(npm:*), Bash(curl:*), Grep
compatibility
Designed for Claude Code
version
1.8.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, enterprise-search, glean

Glean Security Basics

Overview

Glean indexes and searches across an enterprise's entire knowledge base — Confluence, Google Drive, Slack, GitHub, and dozens more connectors. Security concerns center on indexing token management (write-access tokens that can push content into the search index), client token scoping (user-level search permissions), and document-level access controls. A leaked indexing token allows injecting arbitrary content into enterprise search results.

API Key Management

typescript
function createGleanClient(tokenType: "indexing" | "client"): { token: string; baseUrl: string } {
  const token = tokenType === "indexing"
    ? process.env.GLEAN_INDEXING_TOKEN
    : process.env.GLEAN_CLIENT_TOKEN;
  if (!token) {
    throw new Error(`Missing GLEAN_${tokenType.toUpperCase()}_TOKEN — store in secrets manager`);
  }
  // Indexing tokens have WRITE access — never expose in frontend code
  if (tokenType === "indexing") {
    console.log("WARNING: Indexing token loaded — backend use only");
  }
  return { token, baseUrl: `https://${process.env.GLEAN_INSTANCE}.glean.com/api` };
}

Webhook Signature Verification

typescript
import crypto from "crypto";
import { Request, Response, NextFunction } from "express";

function verifyGleanWebhook(req: Request, res: Response, next: NextFunction): void {
  const signature = req.headers["x-glean-signature"] as string;
  const secret = process.env.GLEAN_WEBHOOK_SECRET!;
  const expected = crypto.createHmac("sha256", secret).update(req.body).digest("hex");
  if (!signature || !crypto.timingSafeEqual(Buffer.from(signature), Buffer.from(expected))) {
    res.status(401).send("Invalid signature");
    return;
  }
  next();
}

Input Validation

typescript
import { z } from "zod";

const IndexDocumentSchema = z.object({
  datasource: z.string().min(1).max(100),
  document_id: z.string().min(1).max(500),
  title: z.string().min(1).max(500),
  body: z.string().max(1_000_000),
  allowed_users: z.array(z.string().email()).optional(),
  allowed_groups: z.array(z.string()).optional(),
  permissions_type: z.enum(["public", "restricted", "private"]).default("restricted"),
});

function validateIndexDocument(data: unknown) {
  return IndexDocumentSchema.parse(data);
}

Data Protection

typescript
const GLEAN_SENSITIVE_FIELDS = ["indexing_token", "client_token", "document_body", "user_query", "search_results"];

function redactGleanLog(record: Record<string, unknown>): Record<string, unknown> {
  const redacted = { ...record };
  for (const field of GLEAN_SENSITIVE_FIELDS) {
    if (field in redacted) redacted[field] = "[REDACTED]";
  }
  return redacted;
}

Security Checklist

  • Indexing tokens stored server-side only, never in frontend code
  • Client tokens scoped per-user with X-Glean-Auth-Type header
  • Tokens rotated quarterly via Admin > API Tokens
  • Document permissions set via allowedUsers/allowedGroups
  • SAML SSO enforced for Glean web access
  • All API calls over HTTPS
  • Search audit logs enabled to track sensitive queries
  • Connector permissions reviewed when adding new data sources

Error Handling

VulnerabilityRiskMitigation
Leaked indexing tokenArbitrary content injected into search indexBackend-only storage + rotation
Missing document permissionsConfidential docs exposed in search resultsallowedUsers/allowedGroups on every document
Client token in frontendUser impersonation in search queriesServer-side proxy for search API
Overly broad connector scopeSensitive repos/channels indexed unintentionallyPer-connector permission review
Search queries in logsEmployee activity surveillance riskQuery redaction in logging pipeline

Prerequisites

  • A threat model identifying token custodians, untrusted inputs, source ACL authority, incident owner, and approved secret manager.
  • Separate low-privilege sandbox credentials and fictitious documents for verification; never test with a production token in a shell or CI log.
  • Rotation, revocation, and connector-disable runbooks with a named owner and tested rollback path.
Show full SKILL.md (151 more words)Show less

Instructions

  1. Scope credentials by environment and datasource, inject them from the secret manager, and deny unknown scope or destination.
  2. Validate document schema, size, origin, and ACL before indexing; quarantine failures with opaque correlation IDs.
  3. Verify webhook authenticity before parsing, validate comparable lengths before constant-time comparison, and reject replayed or stale events.
  4. Run synthetic allow and deny probes after ACL or identity changes, logging policy revisions and aggregates rather than content.
  5. Rotate or revoke compromised credentials, disable a connector if integrity is uncertain, and preserve redacted incident evidence.

Output

Return a security receipt with environment, datasource scope, secret-reference version, validation and allow/deny outcomes, rotation/revocation state, incident correlation ID, and rollback action. Never include a token, raw webhook, query, or document body.

Examples

env=staging; source=sandbox-contracts; secret_ref=indexer-v12; signature=pass; allow_probe=pass; deny_probe=pass; rollback=connector-disabled is an auditable control result.

Resources

Next Steps

See glean-prod-checklist.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/.curated/glean-security-basics of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Glean Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Glean Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Glean Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.5kAutomated safety check: PassMIT
GraphQL Operations with CodegenChrisWiles/claude-code-showcase6.1k3 repos~1.5kAutomated safety check: PassNone
Trigger.dev Realtimepapermark/papermark9.2k—~1.7kAutomated safety check: PassCustom licence
Mintlify APImacro-inc/macro4.6k2 repos~333Automated safety check: PassMIT
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT
Reatom Asyncreatom/reatom1.4k—~744Automated safety check: PassMIT

Similar skills

  • GraphQL Operations with Codegen

    ChrisWiles/claude-code-showcase

    Sets the rules for writing GraphQL queries and mutations in .gql files, running codegen, and using generated Apollo hooks with proper error and loading handling.

    6.1k GitHub starsUsed in 3 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • Trigger.dev Realtime

    papermark/papermark

    Shows how to subscribe to Trigger.dev task runs from the backend and from React for progress indicators, live dashboards, AI response streams and approval waits.

    9.2k GitHub stars~1.7k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Mintlify API

    macro-inc/macro

    Interact with the Mintlify REST API to manage deployments, trigger builds, and query documentation site metadata programmatically.

    4.6k GitHub starsUsed in 2 repos~333 tokens
    Backend & APIsAuto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Reatom Async

    reatom/reatom

    Masters Reatom v1001 async flows. An agent skill from reatom/reatom.

    1.4k GitHub stars~744 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Project Security

    johnku2011/boilerplates-with-ai-skills

    A skill your agent uses when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping.

    240 GitHub stars~650 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated yesterday
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed

Questions about Glean Security Basics

What does Glean Security Basics do?

Token security: Indexing tokens have write access -- never expose in frontend. Glean Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Token security: Indexing tokens have write access -- never expose in frontend.

When should I use Glean Security Basics?

Glean Security Basics fits situations like: backend & APIs work in your project.

How do I install Glean Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill glean-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/glean-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/glean-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Glean Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill glean-security-basics -a codex`. Or copy the skill folder (skills/.curated/glean-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/glean-security-basics in your project. Codex loads it when a task matches its description.

Can I use Glean Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill glean-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/glean-security-basics, .gemini/skills/glean-security-basics, .github/skills/glean-security-basics and .opencode/skills/glean-security-basics in your project.

What does Glean Security Basics need to run?

Going by SKILL.md and its folder, Glean Security Basics needs credentials named GLEAN_INDEXING_TOKEN, GLEAN_CLIENT_TOKEN and GLEAN_WEBHOOK_SECRET. Our summary lists: A credential in GLEAN_INDEXING_TOKEN; A credential in GLEAN_CLIENT_TOKEN. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(npm:*), Bash(curl:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Glean Security Basics access the network?

SKILL.md names 2 domains. As links in the text: developers.glean.com and owasp.org. This is read from the text; nothing was executed.

Is Glean Security Basics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Glean Security Basics use?

Glean Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Glean Security Basics use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Glean Security Basics?

Skills that share tags, products or a category with Glean Security Basics: GraphQL Operations with Codegen (ChrisWiles/claude-code-showcase, 6.1k stars), Trigger.dev Realtime (papermark/papermark, 9.2k stars), Mintlify API (macro-inc/macro, 4.6k stars) and Security Review (doorkeeper-gem/doorkeeper, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Glean Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.