Atlas / Skills / jeremylongshore / Lindy Sdk Patterns

Lindy Sdk PatternsSAFE

skills/jeremylongshore/lindy-sdk-patterns

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
1.20.0
Hosts
1 documented
License
MIT
Stars
2,824
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-09
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: lindy-sdk-patterns
description: 'Lindy integration patterns for webhook handling, HTTP actions, and
  Run Code.

  Use when building integrations, calling Lindy agents from code,

  or implementing the Run Code action with Python/JavaScript.

  Trigger with phrases like "lindy integration patterns", "lindy best practices",

  "lindy webhook patterns", "lindy Run Code", "lindy HTTP Request".

  '
allowed-tools: Read, Write, Edit
version: 1.20.0
license: MIT
author: Jeremy Longshore <[email protected]>
tags:
- saas
- lindy
- api
compatibility: Designed for Claude Code
---
# Lindy Integration Patterns

## Overview

Use Lindy's documented integration primitives: **Webhook Received** for inbound
calls, **HTTP Request** for outbound calls, **Run Code** for bounded transformations,
and **Send POST Request to Callback** for the documented callback workflow. This is
not an SDK guide: Lindy's current public documentation does not provide the package,
client, agent CRUD, streaming, API key, or general API-host surface that older copies
of this skill claimed.

## Prerequisites

- Lindy workspace with an editable custom agent
- An application-owned HTTPS endpoint when outbound calls or callbacks are required
- A secret manager for the Lindy-generated Webhook Received secret and any separate
  credential owned by the target application
- Sanitized test fixtures and access to Tasks/Test Panel

## Authentication and Trust Boundaries

- **Inbound to Lindy:** create the webhook in the Webhook Received trigger, select
  **Generate Secret**, store the one-time value, and send it as an Authorization
  bearer value. Use only the generated `public.lindy.ai` webhook URL.
- **Outbound from Lindy:** configure authentication required by the target service in
  the HTTP Request action. This is the target service's credential, not a Lindy API
  key.
- **Callback:** Lindy's webhook guide documents `callbackUrl` and Send POST Request to
  Callback, but does not document a Lindy callback signature. Treat callback content
  as untrusted unless the receiving application establishes its own authenticated
  boundary; never invent or claim a Lindy signing header.
- Keep inbound, outbound, and callback credentials distinct. Never put secrets in a
  prompt, body, query string, task title, log, or Run Code `text` output.

## Instructions

### 1. Configure an Inbound Webhook Received Trigger

1. Add **Webhook Received** and create a named webhook.
2. Generate its secret and store it immediately; Lindy documents that it is shown
   once.
3. Choose follow-up behavior deliberately: same task, new task, or ignore.
4. Define a minimal request schema and reject oversized/unknown fields in the calling
   application before sending.
5. Send a sanitized fixture, then verify the new task in Tasks.

This is a small application wrapper around the documented webhook, not a Lindy SDK:

```typescript
type Intake = { event: 'document.ready'; documentRef: string };

async function triggerLindyWebhook(input: {
  webhookUrl: string;
  webhookSecret: string;
  payload: Intake;
}): Promise<number> {
  const url = new URL(input.webhookUrl);
  if (
    url.protocol !== 'https:' ||
    url.hostname !== 'public.lindy.ai' ||
    !url.pathname.startsWith('/api/v1/webhooks/') ||
    url.username ||
    url.password
  ) {
    throw new Error('Refusing an unrecognized Lindy webhook URL');
  }
  if (!input.webhookSecret.trim()) throw new Error('Webhook secret is empty');
  if (!/^doc_[a-z0-9_-]{1,64}$/i.test(input.payload.documentRef)) {
    throw new Error('Invalid document reference');
  }

  const response = await fetch(url, {
    method: 'POST',
    redirect: 'error',
    headers: {
      Authorization: `Bearer ${input.webhookSecret}`,
      'Content-Type': 'application/json',
    },
    body: JSON.stringify(input.payload),
  });
  if (!response.ok) throw new Error(`Webhook rejected with status ${response.status}`);
  return response.status;
}
```

Do not blindly retry an ambiguous response: the public webhook documentation does not
promise an idempotency key. Check Tasks and the application's operation record before
a controlled retry.

### 2. Configure an Outbound HTTP Request

1. Add **HTTP Request** from Popular or By Lindy.
2. Use a fixed, allowlisted HTTPS URL rather than task-controlled host text.
3. Select the method and content type required by the target service.
4. Put the target service's protected credential in the appropriate header.
5. Constrain the body to named fields from previous steps; omit full source messages,
   headers, credentials, and unrelated context.
6. Branch on the documented status-code/response outputs and fail closed on rejected
   or malformed responses.

### 3. Use Run Code for Bounded Transformation

Lindy documents Python/JavaScript variables as strings and exposes `result`, `text`,
and `stderr` to later steps. Parse, validate, bound, and return only the minimum data:

```python
import json

data = json.loads(raw_items)
if not isinstance(data, list) or len(data) > 100:
    raise ValueError("raw_items must be a list with at most 100 entries")

allowed = []
for item in data:
    if not isinstance(item, dict) or set(item) != {"reference", "score"}:
        raise ValueError("unexpected item schema")
    reference = item["reference"]
    score = item["score"]
    if not isinstance(reference, str) or len(reference) > 64:
        raise ValueError("invalid reference")
    if not isinstance(score, (int, float)) or not 0 <= score <= 1:
        raise ValueError("invalid score")
    if score >= 0.5:
        allowed.append({"reference": reference, "score": score})

return {"count": len(allowed), "items": allowed}
```

Avoid printing input data: printed content becomes `text`. Prefer HTTP Request for
network calls so URL, authentication, response status, and error branches remain
visible in the workflow. Do not rely on an undocumented runtime, sandbox vendor,
startup time, timeout value, or library version; check
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__lindy-sdk-patterns.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-094f83675ca38aSAFEB89first audit
06

Questions

What does the Lindy Sdk Patterns skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Lindy Sdk Patterns safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Lindy Sdk Patterns access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Lindy Sdk Patterns work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement