Atlas / Skills / jeremylongshore / Hubspot Lifecycle And Lists

Hubspot Lifecycle And ListsSAFE

skills/jeremylongshore/hubspot-lifecycle-and-lists

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
2.9.0
Hosts
2 documented
License
MIT
Stars
2,822
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
cursormentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: hubspot-lifecycle-and-lists
description: |
  Manage HubSpot lifecycle stages and list segmentation in production without
  silently destroying CRM trust. Covers lifecycle stage progression guards that
  prevent regression, dynamic list criteria drift, static list orphan detection,
  lead-scoring source-of-truth conflicts, webhook-missed-event recovery, and
  cross-portal list sync. Use when moving contacts through the funnel, building
  segment-based nurture flows, auditing list membership integrity, reconciling
  external lead scores with HubSpot native scoring, or standing up a webhook
  consumer that must never lose a membership-change event. Trigger with "hubspot
  lifecycle", "hubspot list segmentation", "hubspot dynamic list", "hubspot static
  list", "hubspot lead scoring conflict", "lifecycle regression", "list membership
  webhook", "cross-portal list sync".
allowed-tools: Read, Write, Edit, Bash(curl:*), Bash(jq:*), Bash(python3:*), Grep
version: 2.9.0
license: MIT
author: Jeremy Longshore <[email protected]>
compatibility: Designed for Claude Code
tags:
  - hubspot
  - lifecycle
  - segmentation
  - marketing-ops
---

# HubSpot Lifecycle and Lists

## Overview

Move contacts through the HubSpot funnel and maintain list integrity in a production system. This is not a setup walkthrough — it is the code your marketing-ops integration runs when a lifecycle stage update would silently regress a Customer back to Subscriber, when a dynamic list's criteria change orphans members who qualified last week, when a static list import references contacts that were deleted from the portal, when an external lead-scoring model creates a second source of truth that fights HubSpot's native scoring, when a list-membership webhook fires but your consumer returns 5xx and HubSpot never retries, and when an agency needs to mirror list membership across two portals that have no native sync API.

The six production failures this skill prevents:

1. **Lifecycle stage regression** — HubSpot's `PATCH /crm/v3/objects/contacts/{id}` will set lifecyclestage to any valid value regardless of direction. Setting a Customer back to Subscriber silently destroys funnel attribution, invalidates reporting, and corrupts revenue forecasting. The API returns `200 OK`. There is no built-in guard.
2. **Dynamic list criteria drift** — editing a dynamic list's filter criteria does not immediately re-evaluate existing members against the new rules. Members who no longer qualify remain in the list until the nightly background refresh completes, creating a stale membership window of up to 24 hours that can trigger incorrect nurture emails or suppression failures.
3. **Static list import orphans** — contacts added to a static list via import or `POST /contacts/v1/lists/{listId}/add` remain list members even after the underlying contact record is hard-deleted from the CRM. These orphan IDs return errors on any subsequent contact-level API call and pollute downstream sync pipelines.
4. **Lead scoring model disagreement** — writing an external score to a custom contact property while HubSpot's native Lead Scoring tool computes its own score creates two competing signals. Sales works from the HubSpot Score field; marketing automation triggers on the custom property. The two scores diverge and nobody knows which one to trust.
5. **List-membership webhook missed events** — HubSpot's webhook system delivers `contact.propertyChange` events for lifecyclestage updates and list-membership changes via HTTP POST with no retry on 5xx responses. A single downstream outage during a bulk-import window can drop hundreds of membership events permanently with no dead-letter queue or re-delivery mechanism.
6. **Cross-portal list sync** — agencies managing multiple HubSpot portals (e.g., a staging portal mirroring a production portal, or two franchisee portals needing shared suppression lists) have no native API to sync list membership between portals. Manual export-import lags by hours and has no idempotency guarantee.

## Prerequisites

- HubSpot account with a private app token scoped to:
  - `crm.objects.contacts.read`
  - `crm.objects.contacts.write`
  - `crm.lists.read`
  - `crm.lists.write`
  - `crm.schemas.contacts.read` (for lifecycle stage enumeration)
- Python 3.10+ or Node.js 18+ for implementation examples
- `jq` on PATH for shell-level inspection
- `curl` for API verification steps
- For webhook consumption: an HTTPS endpoint reachable by HubSpot's webhook delivery infrastructure
- For cross-portal sync: private app tokens for both portals stored in separate environment variables or a credential router (see `hubspot-auth` skill)

Store all tokens in a secret manager. Never put `pat-na1-*` values in source code or committed `.env` files.

## Instructions

Build in this order. Each section neutralizes one production failure mode.

### 1. Lifecycle stage progression guard (neutralizes regression)

The lifecycle stage enum has a defined forward direction. Any update that moves a contact backward is almost certainly a data pipeline bug, not an intentional business action.

Canonical stage order (HubSpot internal values, not display labels):

```
subscriber → lead → marketingqualifiedlead → salesqualifiedlead → opportunity → customer → evangelist → other
```

`other` is a lateral bucket, not a terminal stage — it sits outside the linear progression and should only be set explicitly.

Never read the stage order from display labels. Display labels are portal-configurable. Always use the internal enum values.

**Progression guard pattern (Python):**

```python
STAGE_ORDER = [
    "subscriber",
    "lead",
    "marketingqualifiedlead",
    "salesqualifiedlead",
    "opportunity",
    "customer",
    "evangelist",
]
# 'other' is not in the linear sequence — treat as a lateral assignment

def stage_index(stage: str) -> int:
    try:
        return STAGE_ORDER.index(stage.lower())
    except ValueError:
        return -1  # 'other
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__hubspot-lifecycle-and-lists.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f83675ca38aSAFEB89first audit
06

Questions

What does the Hubspot Lifecycle And Lists skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Hubspot Lifecycle And Lists safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Hubspot Lifecycle And Lists access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Hubspot Lifecycle And Lists work with?

Its documentation mentions claude-code and cursor. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement