Atlas / Skills / jeremylongshore / Salesloft Reference Architecture

Salesloft Reference ArchitectureSAFE

skills/jeremylongshore/salesloft-reference-architecture

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
1.6.0
Hosts
2 documented
License
MIT
Stars
2,822
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
cursormentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: salesloft-reference-architecture
description: >-
  Design a multi-team Salesloft integration with explicit tenant, auth, client, scheduler, cursor, webhook, queue, reconciliation, and ownership boundaries. Use when reviewing or creating production architecture. Trigger with "Salesloft architecture", "design Salesloft integration", or "Salesloft multi-tenant system".
argument-hint: "[repository-path] [architecture-scope]"
allowed-tools: Read, Glob, Grep, WebFetch, Write, Edit
version: 1.6.0
author: Jeremy Longshore <[email protected]>
license: MIT
tags:
- saas
- salesloft
- architecture
model: inherit
effort: medium
compatibility: Designed for Claude Code
---
# Salesloft Integration Reference Architecture

## Overview

This skill maps Salesloft integration responsibilities into inspectable components and data flows. It treats tenant isolation, rate sharing, and reconciliation as architectural requirements rather than library details.

## Prerequisites

- Business workflows, team topology, data classes, and service objectives
- Auth-flow and endpoint/scope inventory
- Hosting, queue, database, secret-store, and observability constraints
- Named service, security, data, and incident owners

## Tool Discipline

Use `Read`, `Glob`, and `Grep` to inspect repository topology, boundaries, schemas, and deployment files. Use `WebFetch` only for official Salesloft contracts. Use `Write` or `Edit` after confirming the intended architecture artifact.

## Current Contract

- Every request carries an explicit team context and tenant-bound Bearer credential.
- The client preserves endpoint-specific requests, response envelopes, pagination, and rate metadata.
- A scheduler coordinates the team-wide cost budget across workers and integrations.
- Incremental readers persist microsecond `updated_at` cursors with overlap and deduplication.
- Webhook ingress preserves raw bytes, verifies SHA-1 HMAC and callback token, then queues durable idempotent work.

## Authentication

Model separate authorization-code, customer API-key, and private client-credentials lifecycles. Keep encrypted credentials and refresh state keyed by immutable Salesloft team identity.

## Instructions

1. Map actors, Salesloft teams, trust zones, data classes, and all read/write flows.
2. Define tenant context at ingress and carry it through client, queue, cache, database, and logs.
3. Place auth resolution and refresh behind a serialized tenant-bound service.
4. Place request shaping, envelopes, paging, errors, and rate headers behind a narrow client.
5. Separate webhook receipt from processing and pair it with cursor-based reconciliation.
6. Define mutation ownership, idempotency, read-after-write, and repair workflows.
7. Add metrics and runbooks for auth, status, cost, remaining budget, lag, duplicates, and reconciliation.

## Approval Boundaries

Do not centralize mutable global credentials, share tenant caches, accept webhooks before verification, or create a write path without ownership and repair controls.

## Output

Return component and data-flow diagrams, tenant invariants, auth model, endpoint boundaries, rate scheduler, webhook/reconciliation design, failure modes, owners, and open decisions.

## Error Handling

| Condition | Response |
|---|---|
| Tenant context absent | Reject before resolving credentials or data. |
| Queue duplicates | Deduplicate before side effects and retain receipt history. |
| Cursor corruption | Restore last committed checkpoint and replay overlap. |
| Provider/API failure | Degrade boundedly, preserve work, and reconcile after recovery. |

## Examples

The example below shows the minimum redacted evidence expected from a successful invocation of this operator workflow.

```text
teams=12; auth=tenant-bound; limiter=per-team; webhook=verified; reconciliation=daily
```

## Resources

- [Skill-specific official documentation](references/official-docs.md)
- [API basics](https://developers.salesloft.com/docs/platform/api-basics/)
- [Efficient cursor poller](https://developers.salesloft.com/docs/platform/guides/building-an-efficient-cursor-poller/)
- [Webhook introduction](https://developers.salesloft.com/docs/platform/webhooks/introduction/)
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

LOWPrompt injection · review.misleading_scope · CWE-94, CWE-1427
plugins/saas-packs/grammarly-pack/skills/grammarly-license-governor/references/license-management-contract.md
The official user-list contract documents `user_id`, `institution_id`, email, name, `last_activity_at`, and `is_admin`.
Why it matters. This Grammarly license-management API contract appears in two subdirectories of a package whose description and SKILL.md are exclusively about Salesloft architecture, indicating bundled out-of-scope content the description does not disclose.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__salesloft-reference-architecture.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f83675ca38aSAFEB89first audit
06

Questions

What does the Salesloft Reference Architecture skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Salesloft Reference Architecture safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Salesloft Reference Architecture access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Salesloft Reference Architecture work with?

Its documentation mentions claude-code and cursor. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement