Deepgram Ci IntegrationSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: deepgram-ci-integration description: 'Configure Deepgram CI/CD integration for automated testing and deployment. Use when setting up continuous integration pipelines, automated testing, or deployment workflows for Deepgram integrations. Trigger: "deepgram CI", "deepgram CD", "deepgram pipeline", "deepgram github actions", "deepgram automated testing". ' allowed-tools: Read, Write, Edit, Bash(gh:*), Bash(curl:*) version: 1.13.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - deepgram - deployment - testing - ci-cd compatibility: Designed for Claude Code --- # Deepgram CI Integration ## Examples Run unit/schema tests on every pull request with mocked Deepgram responses. Execute one trusted protected-branch integration test against a development project using a short licensed fixture and a scoped secret; retain redacted status/metrics on failure and never inject the key into forked or untrusted CI workflows. ## Overview Set up CI/CD pipelines for Deepgram integrations with GitHub Actions. Includes unit tests with mocked SDK, integration tests against the real API, smoke tests, automated key rotation, and deployment gates. ## Prerequisites - GitHub repository with Actions enabled - `DEEPGRAM_API_KEY` stored as repository secret - `@deepgram/sdk` and `vitest` installed - Test fixtures committed (or downloaded in CI) ## Instructions ### Step 1: GitHub Actions Workflow ```yaml # .github/workflows/deepgram-ci.yml name: Deepgram CI on: push: branches: [main] pull_request: branches: [main] env: NODE_VERSION: '20' jobs: unit-tests: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: ${{ env.NODE_VERSION }} cache: npm - run: npm ci - run: npm run lint - run: npm run typecheck - run: npm test -- --reporter=verbose # Unit tests use mocked SDK — no API key needed integration-tests: runs-on: ubuntu-latest needs: unit-tests if: github.event_name == 'push' || github.event.pull_request.head.repo.full_name == github.repository steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: ${{ env.NODE_VERSION }} cache: npm - run: npm ci - run: npm run test:integration env: DEEPGRAM_API_KEY: ${{ secrets.DEEPGRAM_API_KEY }} timeout-minutes: 5 smoke-test: runs-on: ubuntu-latest needs: integration-tests steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: ${{ env.NODE_VERSION }} cache: npm - run: npm ci && npm run build - name: Smoke test run: npx tsx scripts/smoke-test.ts env: DEEPGRAM_API_KEY: ${{ secrets.DEEPGRAM_API_KEY }} timeout-minutes: 2 ``` ### Step 2: Integration Test Suite ```typescript // tests/integration/deepgram.test.ts import { describe, it, expect, beforeAll } from 'vitest'; import { createClient, DeepgramClient } from '@deepgram/sdk'; const SAMPLE_URL = 'https://static.deepgram.com/examples/Bueller-Life-moves-702702706.wav'; describe('Deepgram Integration', () => { let client: DeepgramClient; beforeAll(() => { const key = process.env.DEEPGRAM_API_KEY; if (!key) throw new Error('DEEPGRAM_API_KEY required for integration tests'); client = createClient(key); }); it('authenticates successfully', async () => { const { result, error } = await client.manage.getProjects(); expect(error).toBeNull(); expect(result.projects.length).toBeGreaterThan(0); }); it('transcribes pre-recorded audio with Nova-3', async () => { const { result, error } = await client.listen.prerecorded.transcribeUrl( { url: SAMPLE_URL }, { model: 'nova-3', smart_format: true } ); expect(error).toBeNull(); const alt = result.results.channels[0].alternatives[0]; expect(alt.transcript).toContain('Life'); expect(alt.confidence).toBeGreaterThan(0.85); }, 30000); it('returns word-level timing', async () => { const { result } = await client.listen.prerecorded.transcribeUrl( { url: SAMPLE_URL }, { model: 'nova-3' } ); const words = result.results.channels[0].alternatives[0].words; expect(words).toBeDefined(); expect(words!.length).toBeGreaterThan(0); expect(words![0]).toHaveProperty('start'); expect(words![0]).toHaveProperty('end'); expect(words![0]).toHaveProperty('confidence'); }, 30000); it('speaker diarization identifies speakers', async () => { const { result } = await client.listen.prerecorded.transcribeUrl( { url: SAMPLE_URL }, { model: 'nova-3', diarize: true } ); const words = result.results.channels[0].alternatives[0].words; expect(words?.some((w: any) => w.speaker !== undefined)).toBe(true); }, 30000); it('TTS generates audio stream', async () => { const response = await client.speak.request( { text: 'CI test.' }, { model: 'aura-2-thalia-en', encoding: 'linear16', container: 'wav' } ); const stream = await response.getStream(); expect(stream).toBeTruthy(); }, 15000); }); ``` ### Step 3: Smoke Test Script ```typescript // scripts/smoke-test.ts import { createClient } from '@deepgram/sdk'; const SAMPLE_URL = 'https://static.deepgram.com/examples/Bueller-Life-moves-702702706.wav'; async function smokeTest() { console.log('Deepgram Smoke Test'); console.log('='.repeat(40)); const client = createClient(process.env.DEEPGRAM_API_KEY!); let passed = 0; let failed = 0; // Test 1: Authentication try { const { error } = await client.manage.getProjects(); if (error) throw error; console.log('[PASS] Authentication'); passed++; } catch (err: any) { console.error(`[FAIL] Authentication: ${err.message}`); failed++; } // Test 2: Pre-record
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__deepgram-ci-integration.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Deepgram Ci Integration skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Deepgram Ci Integration safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Deepgram Ci Integration access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Deepgram Ci Integration work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.