alchemy-security-basics
Analyze and secure Alchemy credentials, browser access, wallet authority, webhook verification, and untrusted chain data
Install / Use
npx skills add jeremylongshore/tons-of-skills-marketplace --skill alchemy-security-basicsInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of alchemy-security-basics
alchemy-security-basics scores 83/100 on our quality scale, 767th of 1,075 Security skills we index.
Its SKILL.md is 4.9 KB long, well organised into 13 sections and no code examples: a solid amount of guidance for an agent.
With 2,785 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 8 days ago, so alchemy-security-basics is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
alchemy-security-basics compared with similar skills
All 4 of these similar skills score higher than alchemy-security-basics; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| alchemy-security-basics (this skill)by jeremylongshore | 83 | 2.8k | 8d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 88.1k | 17d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.3k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.2k | 1d ago | MCP Server |
| crawl4aiby unclecode | 100 | 84.6k | 7d ago | MCP Server |
Frequently asked questions
- How do I install alchemy-security-basics?
- Run
npx skills add jeremylongshore/tons-of-skills-marketplace --skill alchemy-security-basics. The install tabs above show the steps for each supported agent. - Which AI agents does alchemy-security-basics work with?
- It is written for Claude Code, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is alchemy-security-basics safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is alchemy-security-basics still maintained?
- The repository was last updated 8 days ago, so alchemy-security-basics is actively maintained.
Skill content
View source on GitHubname: alchemy-security-basics description: >- Analyze and secure Alchemy credentials, browser access, wallet authority, webhook verification, and untrusted chain data. Use when securing an Alchemy-backed application. Trigger with "secure Alchemy", "Alchemy API key exposure", or "verify an Alchemy webhook". allowed-tools: Read,Glob,Grep,Write,Edit argument-hint: "<application> <credential-class> <runtime>" version: 2.0.0 license: MIT author: Jeremy Longshore jeremy@intentsolutions.io tags: [saas, alchemy, security, web3] model: inherit effort: high compatibility: "Designed for Claude Code; live Alchemy access requires network access, an appropriate credential, account capacity, and explicit approval"
Alchemy Credential and Trust-Boundary Security
Overview
Analyze and secure Alchemy credentials, browser access, wallet authority, webhook verification, and untrusted chain data. This workflow produces a reviewable artifact and negative-path evidence before any live side effect.
Prerequisites
- Current first-party Alchemy documentation for the selected product, chain, feature, client, authentication method, limit, and lifecycle.
- Named product, application, security, data/privacy, budget, release, and operations owners appropriate to the requested scope.
- Synthetic or approved non-production fixtures, a credential canary, explicit success criteria, and a tested rollback boundary.
Current Contract
An Alchemy application key identifies and limits provider access but is not a wallet private key. Frontend use is not categorically forbidden: current guidance supports explicit allowlists and recommends short-lived JWTs where appropriate. Admin keys, Notify tokens, webhook signing keys, and transaction signing authority remain server-side and separately controlled.
Authentication
Create a credential matrix covering application keys, access keys, Admin access, Notify management, webhook verification, and wallet signers. Assign owner, storage, runtime, scopes/allowlists, rotation, revocation, monitoring, and incident procedure to each.
Instructions
- Map browser, edge, server, CI, webhook, admin, and wallet trust boundaries and the data crossing each boundary.
- Choose server header auth for confidential workloads; if browser access is justified, apply exact allowlists or short-lived JWTs and test bypass conditions.
- Validate chain IDs, addresses, block selectors, contract ABIs, method allowlists, response sizes, and remote NFT metadata before use.
- Keep read clients separate from signers; require explicit transaction simulation, user intent, policy checks, and approval in a distinct workflow.
- Verify Notify payloads against the raw body using HMAC-SHA256 and the per-webhook signing key before parsing or side effects.
- Run source, artifact, log, browser-bundle, and configuration secret scans; exercise rotation and incident response before production.
Tool Discipline
Use Read, Glob, and Grep to inspect current documentation, configuration, code, fixtures, and evidence. Use Write and Edit only for approved repository artifacts. Skill invocation alone does not authorize network access, credentials, wallet addresses, customer data, plan changes, spend, key creation or rotation, webhook changes, deployment, replay, transaction construction, signing, broadcast, or deletion.
Approval Boundaries
Security approves browser keys, JWT issuers, secret stores, signing boundaries, and incident response. Wallet transactions, new allowlists, credential rotation, or revocation require the named owner.
Error Handling
- Do not compare webhook signatures with ordinary string equality or after reserializing JSON.
- Do not let an application API key or read client imply transaction-signing permission.
- If credential material is exposed, fail closed, rotate or revoke it, inspect downstream use, and preserve a redacted receipt.
Output
Return the threat model, credential matrix, browser/server decision, input and response controls, signer separation, webhook verification contract, scan evidence, rotation exercise, and open risks. Mark assumptions, observations, source dates, environment-specific behavior, owners, and unresolved gaps explicitly.
Examples
- Approve a restricted browser read only after proving the configured origin allowlist rejects an unlisted origin and the bundle contains no broader credential.
- Reject a webhook whose signature is valid only after JSON reserialization because verification must cover the exact raw body.
Validation
Exercise and record expected and observed results for:
- unlisted browser origin
- expired short-lived JWT
- wrong chain
- oversized response
- bad webhook signature
- secret canary in build artifact
Resources
- Current first-party evidence map — recheck dated Alchemy sources before execution.
- Treat observed account, application, network, indexer, chain, or provider behavior as environment-specific evidence, never a universal guarantee.
Related Skills
Agent-Reach
88.1kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.3kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Scrapling
85.2k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
crawl4ai
84.6kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
