Atlas / Skills / jeremylongshore / Lindy Deploy Integration

Lindy Deploy IntegrationBLOCK

skills/jeremylongshore/lindy-deploy-integration

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
1.20.0
Hosts
1 documented
License
MIT
Stars
2,824
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-09
02

Install

Commands as the repository documents them. They are shown, not run.

npm i -g vercel
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: lindy-deploy-integration
description: 'Deploy applications that integrate with Lindy AI agents.

  Use when deploying webhook receivers, callback handlers,

  or applications connected to Lindy agents.

  Trigger with phrases like "deploy lindy", "lindy deployment",

  "lindy production deploy", "release lindy integration".

  '
allowed-tools: Read, Write, Edit, Bash(gh:*), Bash(docker:*), Bash(npm:*)
version: 1.20.0
license: MIT
author: Jeremy Longshore <[email protected]>
tags:
- saas
- lindy
- deployment
compatibility: Designed for Claude Code
---
# Lindy Deploy Integration

## Overview

Lindy agents run on Lindy's managed infrastructure. Deployment focuses on your
**integration layer**: webhook receivers, callback handlers, and application code
that Lindy agents interact with via HTTP Request actions and webhook triggers.

## Prerequisites

- Lindy agents configured and tested
- Application with webhook receiver endpoints
- Deployment platform (Vercel, Railway, Docker, AWS, GCP)
- Lindy API key and webhook secrets

## Instructions

### Step 1: Prepare Application for Deployment

```typescript
// src/server.ts — Production-ready Lindy webhook receiver
import express from 'express';
import helmet from 'helmet';

const app = express();
app.use(helmet());
app.use(express.json({ limit: '1mb' }));

// Health check for load balancer
app.get('/health', (req, res) => {
  res.json({
    status: 'ok',
    timestamp: new Date().toISOString(),
    version: process.env.APP_VERSION || 'unknown',
  });
});

// Lindy webhook receiver with auth verification
app.post('/lindy/callback', (req, res) => {
  const auth = req.headers.authorization;
  if (auth !== `Bearer ${process.env.LINDY_CALLBACK_SECRET}`) {
    return res.status(401).json({ error: 'Unauthorized' });
  }

  // Respond immediately, process async
  res.json({ received: true });

  // Async processing
  processWebhook(req.body).catch(err => {
    console.error('Webhook processing error:', err);
  });
});

async function processWebhook(payload: any) {
  const { taskId, status, result } = payload;
  // Your business logic here
  console.log(`Task ${taskId}: ${status}`, result);
}

const PORT = process.env.PORT || 3000;
app.listen(PORT, () => console.log(`Listening on :${PORT}`));
```

### Step 2: Docker Deployment

```dockerfile
# Dockerfile
FROM node:20-alpine
WORKDIR /app
COPY package*.json ./
RUN npm ci --production
COPY dist/ ./dist/
EXPOSE 3000
ENV NODE_ENV=production
HEALTHCHECK --interval=30s --timeout=3s \
  CMD wget -qO- http://localhost:3000/health || exit 1
CMD ["node", "dist/server.js"]
```

```bash
# Build and run
docker build -t lindy-integration .
docker run -d \
  -p 3000:3000 \
  -e LINDY_CALLBACK_SECRET="$LINDY_CALLBACK_SECRET" \
  --name lindy-app \
  lindy-integration
```

### Step 3: Vercel Deployment

```bash
# Install Vercel CLI
npm i -g vercel

# Set secrets
vercel secrets add lindy-callback-secret "$LINDY_CALLBACK_SECRET"

# Deploy
vercel --prod
```

```json
// vercel.json
{
  "env": {
    "LINDY_CALLBACK_SECRET": "@lindy-callback-secret"
  }
}
```

### Step 4: Update Lindy Agent Webhook URLs

After deployment, update all Lindy agents with production URLs:

1. In Lindy dashboard, open each agent with a webhook trigger
2. Navigate to the **HTTP Request** action (if agent calls your API)
3. Update URL from dev/staging to production:

   ```
   OLD: https://abc123.ngrok.io/lindy/callback
   NEW: https://api.yourapp.com/lindy/callback
   ```

4. For webhook triggers, callers need the Lindy-generated URL (unchanged)
5. Test with a sample webhook to verify end-to-end

### Step 5: Post-Deploy Verification

```bash
#!/bin/bash
echo "=== Post-Deploy Verification ==="

PROD_URL="https://api.yourapp.com"

# Health check
echo "[1/3] Health check..."
curl -sf "$PROD_URL/health" | jq .

# Webhook endpoint reachable
echo "[2/3] Webhook endpoint..."
STATUS=$(curl -s -o /dev/null -w "%{http_code}" \
  -X POST "$PROD_URL/lindy/callback" \
  -H "Authorization: Bearer $LINDY_CALLBACK_SECRET" \
  -H "Content-Type: application/json" \
  -d '{"test": true}')
echo "Webhook endpoint: HTTP $STATUS (expect 200)"

# Trigger a test agent run
echo "[3/3] Agent trigger test..."
curl -s -X POST "https://public.lindy.ai/api/v1/webhooks/YOUR_ID" \
  -H "Authorization: Bearer $LINDY_TRIGGER_SECRET" \
  -H "Content-Type: application/json" \
  -d '{"event": "deploy.verify", "env": "production"}'
echo "Agent triggered — check Tasks tab in Lindy dashboard"
```

### Step 6: Rollback Plan

```bash
# If deployment fails, rollback:
# Vercel
vercel rollback

# Docker
docker stop lindy-app
docker run -d --name lindy-app-rollback \
  -e LINDY_CALLBACK_SECRET="$LINDY_CALLBACK_SECRET" \
  lindy-integration:previous-tag

# Update Lindy agents back to previous URLs if needed
```

## Output

Produce a deployment receipt with the release identifier, deployed callback
URL, health-check result, authenticated and unauthenticated webhook outcomes,
and the verified Lindy task ID. Keep the previous image or deployment revision
and the corresponding rollback command with that receipt.

## Examples

For a Vercel release, record the production URL, a `GET /health` 200 result,
an unauthenticated callback 401 result, and a successful signed test event.
If the signed callback returns 502, invoke the documented rollback before
changing Lindy agent URLs or retrying the test.

## Deployment Checklist

| Step | Verification |
|------|-------------|
| Build passes | `npm run build` exits 0 |
| Tests pass | `npm test` all green |
| Secrets configured | API key + webhook secret in platform |
| Health check responds | `GET /health` returns 200 |
| Webhook auth works | POST with valid token returns 200 |
| Webhook auth rejects | POST without token returns 401 |
| Lindy agent URLs updated | HTTP Request actions point to prod |
| End-to-end test | Trigger agent, receive callback |

## Error Handling

| Issue | Cause | Solution |
|-------|-------|----------|
| Webhook 502 | A
05

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
SKILL.md:219
| Webhook auth works | POST with valid token returns 200 |
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
SKILL.md:220
| Webhook auth rejects | POST without token returns 401 |
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
references/implementation-guide.md:80
const response = await fetch(`https://api.lindy.ai/v1/agents/${agentId}/run`, {
Why it matters. remote text is to be obeyed as instructions

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-09 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__lindy-deploy-integration.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-094f83675ca38aBLOCKD69first audit
07

Questions

What does the Lindy Deploy Integration skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Lindy Deploy Integration safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What can Lindy Deploy Integration access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Lindy Deploy Integration work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement