ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      codeninja23

      Safety Report

      Native HubSpot

      @codeninja23

      Query and manage HubSpot CRM data via the HubSpot API. Use when you need to search or manage contacts, companies, deals, tickets, or pipelines. Supports crea...

      315Downloads
      1Installs
      18Stars
      2Versions
      API Integration4,971Workflow Automation3,323Search & Retrieval2,116Customer Support1,744

      Security Analysis

      medium confidence
      Clean

      The skill's requests, instructions, and bundled script align with its stated purpose of calling HubSpot's API using a private app token; nothing in the package appears disproportionate or unrelated to that goal.

      Feb 24, 20263 files
      Purpose & Capabilityok

      Name and description state direct HubSpot API access and the package requires python3 plus a HUBSPOT_TOKEN — both are expected for a simple CLI tool that calls api.hubapi.com.

      Instruction Scopeok

      SKILL.md instructs creating a HubSpot private app, setting HUBSPOT_TOKEN, and running the included Python script. The instructions do not ask the agent to read unrelated files or transmit data to other endpoints; they target only api.hubapi.com.

      Install Mechanismok

      No install spec (instruction-only) and the code uses only Python standard library; nothing is downloaded or written to disk outside the included script.

      Credentialsok

      Only HUBSPOT_TOKEN is required and declared as the primary credential. That token is necessary for all described operations (read/write on CRM objects) and the scope list in the README matches the operations.

      Persistence & Privilegeok

      The skill does not request always:true or any system-wide changes. It's user-invocable and does not claim persistent elevated privileges.

      Guidance

      This skill is coherent: it needs your HubSpot private-app token and uses python3 to call api.hubapi.com. Before installing, ensure you: (1) create a HubSpot private app with only the minimum scopes you need, (2) treat the HUBSPOT_TOKEN as a sensitive secret and only supply it to skills you trust, (3) review the full script locally (the provided listing was truncated in the prompt) to confirm there are no unexpected network calls or data exfiltration, and (4) consider using a token with limited write scopes or a token you can rotate if you're concerned.

      Latest Release

      v1.0.1

      Update display name to Native HubSpot

      More by @codeninja23

      Clawpod

      20 stars

      Native Stripe

      16 stars

      Native Linear

      16 stars

      Native Monday

      3 stars

      Native Sentry

      2 stars

      Native Airtable

      2 stars

      Published by @codeninja23 on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]