Apollo Data HandlingSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: apollo-data-handling description: 'Apollo.io data management and compliance. Use when handling contact data, implementing GDPR compliance, or managing data exports and retention. Trigger with phrases like "apollo data", "apollo gdpr", "apollo compliance", "apollo data export", "apollo data retention", "apollo pii". ' allowed-tools: Read, Write, Edit, Bash(kubectl:*), Bash(curl:*) version: 1.13.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - apollo - compliance compatibility: Designed for Claude Code --- # Apollo Data Handling ## Overview Data management, compliance, and governance for Apollo.io contact data. Apollo's database contains 275M+ contacts with PII (emails, phones, LinkedIn profiles). This covers GDPR subject access/erasure, data retention, field-level encryption, and audit logging — using the real Apollo Contacts API endpoints. ## Prerequisites - Apollo master API key (contacts/delete requires master key) - Node.js 18+ ## Instructions ### Step 1: GDPR Subject Access Request (SAR) Find all data Apollo has on a person and export it. ```typescript // src/data/gdpr.ts import axios from 'axios'; const client = axios.create({ baseURL: 'https://api.apollo.io/api/v1', headers: { 'Content-Type': 'application/json', 'x-api-key': process.env.APOLLO_API_KEY! }, }); interface SubjectAccessReport { email: string; dataFound: boolean; crmContact?: Record<string, any>; apolloDatabaseMatch?: Record<string, any>; activeSequences: string[]; exportedAt: string; } export async function handleSAR(email: string): Promise<SubjectAccessReport> { const report: SubjectAccessReport = { email, dataFound: false, activeSequences: [], exportedAt: new Date().toISOString(), }; // 1. Search your CRM contacts (contacts you've saved) const { data: crmData } = await client.post('/contacts/search', { q_keywords: email, per_page: 1, }); if (crmData.contacts?.length > 0) { const c = crmData.contacts[0]; report.dataFound = true; report.crmContact = { id: c.id, name: c.name, email: c.email, title: c.title, phone: c.phone_numbers, organization: c.organization_name, city: c.city, state: c.state, country: c.country, createdAt: c.created_at, updatedAt: c.updated_at, contactStage: c.contact_stage_id, labels: c.label_ids, }; report.activeSequences = c.emailer_campaign_ids ?? []; } // 2. Check Apollo's database (enrichment data) try { const { data: enrichData } = await client.post('/people/match', { email }); if (enrichData.person) { report.dataFound = true; report.apolloDatabaseMatch = { name: enrichData.person.name, title: enrichData.person.title, seniority: enrichData.person.seniority, city: enrichData.person.city, linkedinUrl: enrichData.person.linkedin_url, organization: enrichData.person.organization?.name, }; } } catch { /* person not found in Apollo DB */ } return report; } ``` ### Step 2: Right to Erasure (Delete) ```typescript export async function handleErasure(email: string): Promise<{ email: string; erased: boolean; sequencesRemoved: number; }> { // 1. Find the CRM contact const { data } = await client.post('/contacts/search', { q_keywords: email, per_page: 1, }); const contact = data.contacts?.[0]; if (!contact) return { email, erased: false, sequencesRemoved: 0 }; // 2. Remove from all sequences first let sequencesRemoved = 0; const sequenceRemovalFailures: string[] = []; for (const seqId of contact.emailer_campaign_ids ?? []) { try { await client.post('/emailer_campaigns/remove_or_stop_contact_ids', { emailer_campaign_id: seqId, contact_ids: [contact.id], }); sequencesRemoved++; } catch (err: any) { // Do not delete while the contact may still receive outreach. sequenceRemovalFailures.push(seqId); } } if (sequenceRemovalFailures.length > 0) { throw new Error(`Erasure paused: removal failed for ${sequenceRemovalFailures.length} sequence(s)`); } // 3. Delete the contact from your CRM (requires master key) await client.delete(`/contacts/${contact.id}`); return { email, erased: true, sequencesRemoved }; } ``` ### Step 3: Data Retention Policy ```typescript // src/data/retention.ts interface RetentionPolicy { maxAgeDays: number; inactiveThresholdDays: number; protectedLabels: string[]; // label IDs to never auto-delete } export async function enforceRetention(policy: RetentionPolicy) { const cutoff = new Date(); cutoff.setDate(cutoff.getDate() - policy.maxAgeDays); // Search for old contacts const { data } = await client.post('/contacts/search', { sort_by_field: 'contact_created_at', sort_ascending: true, per_page: 100, }); const candidates = data.contacts.filter((c: any) => { if (new Date(c.created_at) > cutoff) return false; // Skip contacts with protected labels const labels = c.label_ids ?? []; return !policy.protectedLabels.some((l) => labels.includes(l)); }); console.log(`Found ${candidates.length} contacts past ${policy.maxAgeDays}-day retention`); let deleted = 0; for (const contact of candidates) { try { await client.delete(`/contacts/${contact.id}`); deleted++; } catch (err: any) { console.error(`Failed to delete ${contact.name}: ${err.message}`); } } return { evaluated: data.contacts.length, deleted }; } ``` ### Step 4: Field-Level Encryption for Local Storage ```typescript // src/data/encryption.ts import crypto from 'crypto'; const KEY = Buffer.from(process.env.APOLLO_ENCRYPTION_KEY!, 'hex'); // 32 bytes const ALGO = 'aes-256-gcm'; export function encrypt(plaintext: string): string { const iv = crypto.randomBytes(16); const cipher = crypto.createCipheriv(ALGO, KEY, iv); let enc = cipher.update(plaintext, 'utf8', 'hex'); enc += cipher.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__apollo-data-handling.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Apollo Data Handling skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Apollo Data Handling safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Apollo Data Handling access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Apollo Data Handling work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.