attio-security-basics

v2026.09.24

Harden an Attio integration with least-privilege credentials, tenant isolation, log redaction, raw-body webhook verification, idempotency, and incident-ready rotation. Use when reviewing Attio security controls or preparing production access. Trigger with "Attio security", "secure Attio integration", or "Attio webhook signature".

GitHub
安装命令
npx skhub add jeremylongshore/attio-security-basics
Markdown
SKILL.md

Attio Integration Security Baseline

Overview

This skill audits and hardens Attio authentication, data handling, webhook verification, tenant boundaries, and operational response without exposing secrets or customer records.

Prerequisites

  • Data-flow and trust-boundary inventory
  • Endpoint-to-scope map and tenant model
  • Secret-store, logging, retention, and incident-response owners
  • Webhook receiver code when events are enabled

Tool Discipline

Use Read, Glob, and Grep to inspect credential flow, authorization, logs, storage, and webhook handling. Use WebFetch only for current official Attio security contracts. Use Write or Edit after findings, target controls, and rollback conditions are approved.

Current Contract

  • Tokens should be least-privilege, stored server-side, tenant-bound, redacted, and rotatable.
  • Verify Attio-Signature by computing SHA-256 HMAC over the exact raw UTF-8 request body with the webhook secret and comparing equal-length hexadecimal values in constant time.
  • The signature input is the raw body only; do not invent a timestamp concatenation protocol.
  • Delivery is at least once. Use Idempotency-Key and durable state to control duplicates; signature verification alone is not deduplication.

Authentication

Prefer OAuth for multi-workspace applications and a workspace key for a controlled single workspace. Enforce server-side workspace authorization before resolving the encrypted token.

Instructions

  1. Map secrets, tenant context, Attio data, logs, queues, backups, and administrative paths.
  2. Compare used endpoints with granted scopes and remove unjustified privilege through an approved rotation.
  3. Enforce tenant authorization before credential resolution and storage access.
  4. Redact authorization headers, secrets, raw customer payloads, and sensitive attribute values from telemetry.
  5. Preserve the raw webhook body, verify its HMAC before parsing, compare equal-length buffers safely, and reject failures.
  6. Deduplicate accepted events by Idempotency-Key, queue work, and reconcile downstream state.
  7. Exercise token revocation, webhook-secret rotation, audit review, and incident rollback.

Approval Boundaries

Do not rotate production secrets, reduce retention, change access scopes, or replay customer mutations without the responsible security and service owners.

Output

Return the threat boundaries, scope gaps, secret lifecycle, webhook verification evidence, redaction tests, tenant-isolation tests, and remediation owners.

Error Handling

ConditionResponse
Raw webhook body is unavailableReject the event and fix middleware ordering.
Signature lengths differReject before constant-time comparison.
Token appears in retained outputRevoke or rotate it and scrub the artifact.
Duplicate idempotency key arrivesAcknowledge without repeating committed work.

Examples

Input:

scope=oauth service plus webhook receiver; environment=production candidate

Expected handoff:

least-privilege=verified; hmac=raw-body; dedupe=durable; rotation=exercised

Resources

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

skills/.curated/attio-security-basics

默认分支

main

最新提交

e5a6c3b

Tree SHA

c2dc8e8