flexport-security-basics
Installation
SKILL.md
Flexport Integration Security Baseline
Overview
Protect four high-value boundaries: OAuth/API credentials, cached tokens, webhook secrets/raw bodies, and business mutations that can create freight or trade records.
Prerequisites
- Threat model with account, workload, and data boundaries
- Endpoint-scoped credential plan and broad-key exception register
- Secret scanning, redacted telemetry, rotation, and incident procedures
Instructions
Step 1: Minimize credentials
Prefer distinct endpoint-scoped OAuth clients. Treat API keys as broad-access exceptions and never record secret values or suffixes.