Assemblyai Upgrade MigrationSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: assemblyai-upgrade-migration description: >- Migrate legacy AssemblyAI Streaming v2 and LeMUR integrations to Streaming v3 and LLM Gateway with parity evidence. Use when removing deprecated contracts. Trigger with "migrate AssemblyAI", "LeMUR migration", or "Streaming v3 upgrade". allowed-tools: Read,Glob,Grep,Write,Edit argument-hint: "<repository-path> <legacy-surface>" version: 1.12.0 license: MIT author: Jeremy Longshore <[email protected]> tags: [saas, assemblyai] model: inherit effort: high compatibility: "Designed for Claude Code; live AssemblyAI work requires network access" --- # AssemblyAI v3 and LLM Gateway Migration ## Overview Migrate legacy AssemblyAI Streaming v2 and LeMUR integrations to Streaming v3 and LLM Gateway with parity evidence. Treat live audio, transcript content, credentials, spend, and destructive state as separately governed boundaries. ## Prerequisites - The target repository or integration path and the requested operator outcome. - The AssemblyAI project, environment, region, data classification, and accountable owner. - Current first-party documentation plus credentials only for a narrowly approved live check. ## Current Contract Streaming v2 used `/v2/realtime/ws`; v3 uses `/v3/ws` with different messages, turns, configuration, and termination. LeMUR sunset on March 31, 2026; LLM Gateway is the current analysis path. Deprecated transcript summary parameters must not anchor new designs. ## Authentication For live work, inject `ASSEMBLYAI_API_KEY` from an approved secret manager and send the raw value only in the AssemblyAI `Authorization` header to the configured first-party host. Never print, commit, place in a URL, or expose it to an untrusted client. Callback secrets and temporary streaming tokens are separate credentials. ## Instructions 1. Inventory endpoints, SDK methods, handlers, fixtures, dashboards, and legacy credentials. 2. Capture approved legacy behavior with synthetic golden cases. 3. Map v2 messages and shutdown to v3 begin, turns, configuration, and termination. 4. Map LeMUR prompts and outputs to schema-constrained LLM Gateway requests. 5. Compare quality, latency, structured results, privacy, and cost. 6. Canary the new route, test rollback, then remove legacy code and secrets. ## Tool Discipline Use Read, Glob, and Grep to inspect repository code, configuration, fixtures, and evidence. Use Write and Edit only for approved implementation or documentation changes. Do not call AssemblyAI, upload audio, open a streaming session, mint a token, replay a callback, deploy, rotate a key, or delete a transcript merely because this skill was invoked. ## Approval Boundaries Require an accountable owner before live audio processing, production credential or endpoint changes, paid model or capacity changes, content retention, callback replay, deployment, or deletion. Read-only repository inspection and synthetic offline validation do not authorize live vendor actions. ## Failure Modes - Changing only the WebSocket URL leaves v2 handlers broken. - LeMUR calls after sunset are a hard migration defect. - LLM parity needs semantic and schema assertions, not byte equality. ## Output Return the operation scope, environment, region, contract surface, authorization class, model and feature decisions, deterministic validation results, content-free identifiers, risks, cleanup or rollback state, and a concise pass/fail receipt. Exclude credentials, signed URLs, audio, transcript text, prompts, and customer-derived content. ## Example - Start with the named environment, approved regional host, synthetic fixture identity, and bounded operation budget. - Finish with safe IDs, contract and assertion counts, terminal state, cleanup status, and the decision owner; never reproduce speech content. ## Validation Rerun the smallest relevant deterministic check, compare actual state with the requested outcome and current first-party contract, verify sensitive fields are absent from evidence, and confirm rollback, termination, or deletion state before reporting success. ## References Review the dated first-party evidence map before relying on any model, parameter, limit, price, region, or lifecycle claim. - [Current first-party evidence map](references/official-docs.md)
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__assemblyai-upgrade-migration.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Assemblyai Upgrade Migration skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Assemblyai Upgrade Migration safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Assemblyai Upgrade Migration access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Assemblyai Upgrade Migration work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.