Atlas / Skills / jeremylongshore / Elevenlabs Security Basics

Elevenlabs Security BasicsCAUTION

skills/jeremylongshore/elevenlabs-security-basics

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
1.6.0
Hosts
1 documented
License
MIT
Stars
2,822
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: elevenlabs-security-basics
description: |
  Apply ElevenLabs security best practices for API keys, webhook HMAC
  validation, and voice data protection.
  Use when securing API keys, validating webhook signatures, or auditing
  ElevenLabs security configuration.
  Trigger with "elevenlabs security", "elevenlabs secrets", "secure elevenlabs",
  "elevenlabs API key security", "elevenlabs webhook signature",
  "elevenlabs HMAC".
allowed-tools: Read, Write, Grep
version: 1.6.0
license: MIT
author: Jeremy Longshore <[email protected]>
tags:
- saas
- voice
- ai
- elevenlabs
- security
- webhooks
compatibility: Designed for Claude Code
---
# ElevenLabs Security Basics

## Overview

Security best practices for ElevenLabs API key management, webhook HMAC
signature verification, and protecting cloned voice data. ElevenLabs uses a
single API key (`xi-api-key`) and HMAC webhook authentication.

This SKILL.md carries the workflow at a high level with the essential
skeletons. Full production code for each step lives in
[references/implementation.md](references/implementation.md), and end-to-end
scenarios live in [references/examples.md](references/examples.md).

## Prerequisites

- ElevenLabs SDK installed
- Understanding of environment variables
- Access to ElevenLabs dashboard (Settings > API Keys)

## Instructions

### Step 1: API Key Management

Keep keys out of source, and add a hook that blocks accidental commits:

```bash
# .env (NEVER commit to git)
ELEVENLABS_API_KEY=sk_your_key_here

# .gitignore — MUST include these
.env
.env.local
.env.*.local
```

```bash
#!/bin/bash
# .git/hooks/pre-commit — reject staged ElevenLabs keys
if git diff --cached | grep -qE 'sk_[a-zA-Z0-9]{20,}'; then
  echo "ERROR: ElevenLabs API key detected in staged changes!"
  echo "Remove the key and use environment variables instead."
  exit 1
fi
```

### Step 2: Environment-Specific Keys

Load the key at startup, fail fast when it is missing, and warn if a production
key leaks into development. Full `getSecurityConfig()` implementation:
[references/implementation.md](references/implementation.md).

### Step 3: Webhook HMAC Signature Verification

ElevenLabs webhooks carry an `ElevenLabs-Signature` header formatted as
`t=TIMESTAMP,v1=SIGNATURE`. Verify it with HMAC-SHA256, reject timestamps older
than 5 minutes (replay protection), and use a timing-safe comparison. Full
`verifyWebhookSignature()` implementation:
[references/implementation.md](references/implementation.md).

### Step 4: Express Webhook Endpoint with Verification

Verify against the **raw** request body, respond 200 fast, then process
asynchronously so you never trip the webhook timeout. Full endpoint:
[references/implementation.md](references/implementation.md).

### Step 5: API Key Rotation Procedure

Generate the new key, validate it before cutover, push to every environment,
verify production, then revoke the old key — zero downtime. Full runbook:
[references/implementation.md](references/implementation.md).

### Step 6: Voice Data Protection

Cloned voices are biometric PII: restrict who can clone, audit-log every
operation, and require documented consent. Full policy and audit logger:
[references/implementation.md](references/implementation.md).

## Output

Applying this skill produces a hardened ElevenLabs integration:

- API keys stored only in environment variables, with `.env` gitignored and a
  pre-commit hook that blocks the `sk_` key pattern.
- A `verifyWebhookSignature()` helper and Express endpoint that reject invalid
  signatures (HTTP 401) and replayed requests (timestamp > 5 minutes).
- A documented, zero-downtime key rotation runbook.
- Structured audit logs (`elevenlabs.voice.audit`) for every voice clone,
  delete, and use, plus a completed Security Checklist below.

## Security Checklist

- [ ] API keys in environment variables (never in source code)
- [ ] `.env` files in `.gitignore`
- [ ] Different API keys for dev/staging/prod
- [ ] Pre-commit hook scanning for key patterns (`sk_`)
- [ ] Webhook signatures verified with HMAC-SHA256
- [ ] Replay protection on webhooks (5-minute timestamp check)
- [ ] Webhook failures monitored (auto-disabled after 10 consecutive failures)
- [ ] Voice cloning operations audit-logged
- [ ] Cloned voice consent documented
- [ ] API key rotation scheduled quarterly

## Webhook Failure Policy

ElevenLabs auto-disables webhooks after:

- 10+ consecutive delivery failures, AND
- Last successful delivery was 7+ days ago (or never delivered)

Always return HTTP 200 quickly from your webhook handler.

## Error Handling

| Security Issue | Detection | Mitigation |
|----------------|-----------|------------|
| Exposed API key | Git scanning, CI check | Rotate immediately, revoke old key |
| Invalid webhook signature | `verifyWebhookSignature()` returns false | Log and reject (HTTP 401) |
| Replay attack | Timestamp > 5 minutes old | Reject with timestamp check |
| Unauthorized voice cloning | Audit logs | Restrict clone permissions |

## Examples

Worked, end-to-end scenarios live in
[references/examples.md](references/examples.md):

- **Block a key commit before it happens** — the pre-commit hook aborts a
  commit containing `sk_...`.
- **Reject a replayed webhook** — a correct HMAC still fails on a 6-minute-old
  timestamp.
- **Rotate a leaked production key with zero downtime** — validate the new key,
  cut over, then revoke.
- **Audit a voice-clone operation** — structured JSON proving who cloned a
  voice and whether consent was on file.

## Resources

- [ElevenLabs Webhooks](https://elevenlabs.io/docs/product-guides/administration/webhooks)
- [ElevenLabs API Keys](https://elevenlabs.io/app/settings/api-keys)
- [Voice Cloning Policy](https://elevenlabs.io/safety)

## Next Steps

Once these basics are in place, harden the wider deployment: apply the
`elevenlabs-prod-checklist` skill for production readiness, schedule the
quarterly key rotation from Step 5, and wire the voice audit logs i
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SKILL.md:41
- Access to ElevenLabs dashboard (Settings > API Keys)
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
references/implementation.md:9
Load and validate the API key at startup, and warn loudly if a production key
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__elevenlabs-security-basics.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f83675ca38aCAUTIONB89first audit
06

Questions

What does the Elevenlabs Security Basics skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Elevenlabs Security Basics safe to install?

With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Elevenlabs Security Basics access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Elevenlabs Security Basics work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement