Atlas / Skills / jeremylongshore / Granola Sdk Patterns

Granola Sdk PatternsBLOCK

skills/jeremylongshore/granola-sdk-patterns

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
1.13.0
Hosts
1 documented
License
MIT
Stars
2,823
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: granola-sdk-patterns
description: 'Zapier automation patterns and Enterprise API integration for Granola.

  Use when building automated workflows, connecting Granola to 8,000+ apps via Zapier,

  or querying the Enterprise API for notes and transcripts.

  Trigger: "granola zapier", "granola automation", "granola API", "granola SDK".

  '
allowed-tools: Read, Write, Edit, Bash(curl:*)
version: 1.13.0
license: MIT
author: Jeremy Longshore <[email protected]>
tags:
- saas
- granola
- automation
- api
compatibility: Designed for Claude Code
---
# Granola SDK Patterns

## Overview

Granola does not have a traditional SDK. Integration is achieved through three channels: Zapier (8,000+ app connections), the Enterprise API (REST, workspace-level read access), and native integrations (Slack, Notion, HubSpot, Attio, Affinity). This skill covers automation patterns for all three.

## Prerequisites

- Granola Business plan ($14/user/month) for Zapier + native CRM
- Enterprise plan ($35+/user/month) for API access
- Zapier account for automation workflows

## Instructions

### Step 1 — Understand Zapier Triggers

Granola provides two Zapier triggers:

| Trigger | Fires When | Use Case |
|---------|-----------|----------|
| **Note Added to Granola Folder** | A note is placed in a specific folder | Auto-route by meeting type |
| **Note Shared to Zapier** | You manually share a note to Zapier | Selective sharing for important meetings |

**Webhook payload data available:**

- `title` — meeting title from calendar
- `creator_name` / `creator_email` — note creator
- `attendees[]` — array of `{name, email}` objects
- `calendar_event_title` — original calendar event name
- `calendar_event_datetime` — meeting date/time
- `note_content` — the enhanced note content (Markdown)

### Step 2 — Build Common Zap Patterns

**Pattern 1: Meeting Notes to Notion (auto-archive)**

```yaml
Trigger: Note Added to Granola Folder ("All Meetings")
Action: Notion — Create Database Item
  Database: Meeting Archive
  Title: "{{title}}"
  Date: "{{calendar_event_datetime}}"
  Content: "{{note_content}}"
  Attendees: "{{attendees}}"
```

**Pattern 2: Action Items to Asana/Linear**

```yaml
Trigger: Note Shared to Zapier
Filter: note_content contains "Action Items"
Code Step (JavaScript):
  const lines = inputData.note_content.split('\n');
  const actions = lines
    .filter(l => l.match(/^- \[ \]/))
    .map(l => l.replace('- [ ] ', ''));
  output = actions.map(a => ({task: a}));
Action: Linear — Create Issue (for each action)
  Title: "{{task}}"
  Team: Engineering
  Label: "meeting-action"
```

**Pattern 3: Sales Call Summary to Slack + HubSpot**

```yaml
Trigger: Note Added to Granola Folder ("Sales Calls")
Path A — Slack:
  Action: Post Message to #sales-updates
  Message: |
    *New Sales Call:* {{title}}
    *Attendees:* {{attendees}}

    {{note_content}}

    [View full notes in Granola]

Path B — HubSpot (via Zapier if not using native):
  Action: Find Contact by Email ({{attendees[0].email}})
  Action: Create Engagement Note
    Body: "{{note_content}}"
```

**Pattern 4: Meeting Follow-Up Email**

```yaml
Trigger: Note Shared to Zapier
Action: ChatGPT — Generate Follow-Up Email
  Prompt: "Write a professional follow-up email based on: {{note_content}}"
Action: Gmail — Create Draft
  To: "{{attendees}}"
  Subject: "Follow-up: {{title}}"
  Body: "{{chatgpt_response}}"
Action: Slack — Notify
  Message: "Follow-up draft ready for: {{title}}"
```

### Step 3 — Use the Enterprise API

Available on Enterprise plan. API keys generated at Settings > API Keys (up to 5 per workspace).

```bash
# List all accessible notes (paginated)
curl -s "https://api.granola.ai/v0/notes" \
  -H "Authorization: Bearer $GRANOLA_API_KEY" \
  -H "Content-Type: application/json" | jq '.notes[:3]'

# Get a specific note with transcript
curl -s "https://api.granola.ai/v0/notes/{note_id}" \
  -H "Authorization: Bearer $GRANOLA_API_KEY" | jq '{title, summary, action_items}'
```

**API characteristics:**

- Bearer token authentication
- Read-only access to publicly shared notes within your workspace
- Rate limited per workspace (429 response when exceeded)
- Pagination for list endpoints

**Reverse-engineered endpoints (unofficial, for reference):**

```
POST https://api.granola.ai/v2/get-documents    # List documents (paginated)
POST https://api.granola.ai/v1/get-document-transcript  # Get transcript
POST https://api.granola.ai/v1/get-workspaces    # List workspaces
POST https://api.granola.ai/v1/get-documents-batch  # Bulk fetch by IDs
```

Authentication uses WorkOS with refresh token rotation via `POST https://api.workos.com/user_management/authenticate`.

### Step 4 — Multi-Step Automation Chains

```yaml
Name: Complete Meeting Follow-Up Pipeline

Step 1 — Trigger:
  Granola: Note Added to Folder ("Client Meetings")

Step 2 — Filter:
  Only continue if attendees contain external email domains

Step 3 — Action:
  ChatGPT: Generate structured summary and follow-up email

Step 4 — Action:
  Gmail: Create draft follow-up email to external attendees

Step 5 — Action:
  Notion: Create page in Client Meeting Log database

Step 6 — Action:
  Linear: Create issues from action items with "client" label

Step 7 — Action:
  Slack: Post summary to #client-updates channel

Step 8 — Action:
  HubSpot: Log meeting note on matched Contact/Deal
```

### Step 5 — Folder-Based Routing

Organize Granola folders to drive different Zap behaviors:

| Folder | Zapier Trigger | Actions |
|--------|---------------|---------|
| `Sales Calls` | Auto | Slack #sales + HubSpot + follow-up email |
| `Engineering` | Auto | Linear tasks + Notion wiki |
| `All Hands` | Auto | Slack #general + Google Drive archive |
| `Interviews` | Manual share | Greenhouse scorecard + hiring panel Slack |
| `1-on-1s` | None | Private, no automation |

## Output

- Zapier workflows configured for automated note processing
- API access established for custom integrations
- Multi-step
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
SKILL.md:151
Authentication uses WorkOS with refresh token rotation via `POST https://api.workos.com/user_management/authenticate`.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__granola-sdk-patterns.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f83675ca38aBLOCKD69first audit
06

Questions

What does the Granola Sdk Patterns skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Granola Sdk Patterns safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What can Granola Sdk Patterns access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Granola Sdk Patterns work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement