Deepgram Core Workflow BSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: deepgram-core-workflow-b description: 'Implement real-time streaming transcription with Deepgram WebSocket. Use when building live transcription, voice interfaces, real-time captioning, or voice AI applications. Trigger: "deepgram streaming", "real-time transcription", "live transcription", "websocket transcription", "voice streaming", "deepgram live". ' allowed-tools: Read, Write, Edit, Bash(npm:*), Bash(pip:*), Grep version: 1.13.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - deepgram - voice-ai - transcription - streaming - websocket compatibility: Designed for Claude Code --- # Deepgram Core Workflow B: Live Streaming Transcription ## Examples Open a development streaming session with a non-sensitive test utterance, verify connection/authentication, partial/final transcript state, timeout, and close behavior. Enforce the session's data/consent policy and log a correlation ID plus state transitions—not audio bytes, API keys, or full participant speech. ## Overview Real-time streaming transcription using Deepgram's WebSocket API. The SDK manages the WebSocket connection via `listen.live()`. Covers microphone capture, interim/final result handling, speaker diarization, UtteranceEnd detection, auto-reconnect, and building an SSE endpoint for browser clients. ## Prerequisites - `@deepgram/sdk` installed, `DEEPGRAM_API_KEY` configured - Audio source: microphone (via Sox/`rec`), file stream, or WebSocket audio from browser - For mic capture: `sox` installed (`apt install sox` / `brew install sox`) ## Instructions ### Step 1: Basic Live Transcription ```typescript import { createClient, LiveTranscriptionEvents } from '@deepgram/sdk'; const deepgram = createClient(process.env.DEEPGRAM_API_KEY!); const connection = deepgram.listen.live({ model: 'nova-3', language: 'en', smart_format: true, punctuate: true, interim_results: true, // Show in-progress results utterance_end_ms: 1000, // Silence threshold for utterance end vad_events: true, // Voice activity detection events encoding: 'linear16', // 16-bit PCM sample_rate: 16000, // 16 kHz channels: 1, // Mono }); // Connection lifecycle events connection.on(LiveTranscriptionEvents.Open, () => { console.log('WebSocket connected to Deepgram'); }); connection.on(LiveTranscriptionEvents.Close, () => { console.log('WebSocket closed'); }); connection.on(LiveTranscriptionEvents.Error, (err) => { console.error('Deepgram error:', err); }); // Transcript events connection.on(LiveTranscriptionEvents.Transcript, (data) => { const transcript = data.channel.alternatives[0]?.transcript; if (!transcript) return; if (data.is_final) { console.log(`[FINAL] ${transcript}`); } else { process.stdout.write(`\r[interim] ${transcript}`); } }); // UtteranceEnd — fires when speaker pauses connection.on(LiveTranscriptionEvents.UtteranceEnd, () => { console.log('\n--- utterance end ---'); }); ``` ### Step 2: Microphone Capture with Sox ```typescript import { spawn } from 'child_process'; function startMicrophone(connection: any) { // Sox captures from default mic: 16kHz, 16-bit signed LE, mono const mic = spawn('rec', [ '-q', // Quiet (no progress) '-r', '16000', // Sample rate '-e', 'signed', // Encoding '-b', '16', // Bit depth '-c', '1', // Mono '-t', 'raw', // Raw PCM output '-', // Output to stdout ]); mic.stdout.on('data', (chunk: Buffer) => { if (connection.getReadyState() === 1) { // WebSocket.OPEN connection.send(chunk); } }); mic.on('error', (err) => { console.error('Microphone error:', err.message); console.log('Install sox: apt install sox / brew install sox'); }); return mic; } // Usage const mic = startMicrophone(connection); // Graceful shutdown process.on('SIGINT', () => { mic.kill(); connection.finish(); // Sends CloseStream message, waits for final results setTimeout(() => process.exit(0), 2000); }); ``` ### Step 3: Live Diarization ```typescript const connection = deepgram.listen.live({ model: 'nova-3', smart_format: true, diarize: true, interim_results: false, // Only final for cleaner diarization utterance_end_ms: 1500, encoding: 'linear16', sample_rate: 16000, channels: 1, }); connection.on(LiveTranscriptionEvents.Transcript, (data) => { if (!data.is_final) return; const words = data.channel.alternatives[0]?.words ?? []; if (words.length === 0) return; // Group consecutive words by speaker let currentSpeaker = words[0].speaker; let segment = ''; for (const word of words) { if (word.speaker !== currentSpeaker) { console.log(`Speaker ${currentSpeaker}: ${segment.trim()}`); currentSpeaker = word.speaker; segment = ''; } segment += ` ${word.punctuated_word ?? word.word}`; } console.log(`Speaker ${currentSpeaker}: ${segment.trim()}`); }); ``` ### Step 4: Auto-Reconnect with Backoff ```typescript class ReconnectingLiveTranscription { private client: ReturnType<typeof createClient>; private connection: any = null; private reconnectAttempts = 0; private maxReconnectAttempts = 10; private baseDelay = 1000; constructor(apiKey: string, private options: Record<string, any>) { this.client = createClient(apiKey); } connect() { this.connection = this.client.listen.live(this.options); this.connection.on(LiveTranscriptionEvents.Open, () => { console.log('Connected'); this.reconnectAttempts = 0; // Reset on success }); this.connection.on(LiveTranscriptionEvents.Close, () => { this.scheduleReconnect(); }); this.connection.on(LiveTranscriptionEvents.Error, (err: Error) => { console.error('Connection error:', err.message); this.scheduleReconnect(); }); return this.connection; } private scheduleReconnect() {
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__deepgram-core-workflow-b.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Deepgram Core Workflow B skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Deepgram Core Workflow B safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Deepgram Core Workflow B access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Deepgram Core Workflow B work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.