Deepgram Reference ArchitectureSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: deepgram-reference-architecture description: 'Implement Deepgram reference architecture for scalable transcription systems. Use when designing transcription pipelines, building production architectures, or planning Deepgram integration at scale. Trigger: "deepgram architecture", "transcription pipeline", "deepgram system design", "deepgram at scale", "enterprise deepgram", "deepgram queue". ' allowed-tools: Read, Write, Edit, Bash(npm:*) version: 1.13.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - deepgram - architecture - scaling compatibility: Designed for Claude Code --- # Deepgram Reference Architecture ## Prerequisites - A documented audio/transcript data flow, consent/retention policy, approved environment boundaries, and service/data owners. - Reviewed interfaces for auth, media ingestion, callbacks, observability, storage, and incident response. ## Examples Model a development producer that validates media metadata, sends a request using a scoped project key, receives a signed callback, and records only correlation/state metrics. Promote the same versioned contract through staging before a production canary, retaining a dead-letter/recovery owner and excluding audio/transcript content from telemetry. ## Overview Four reference architectures for Deepgram transcription at scale: synchronous REST for short files, async queue (BullMQ) for batch processing, WebSocket proxy for real-time streaming, and a hybrid router that auto-selects the best pattern based on audio duration. ## Architecture Selection Guide | Pattern | Best For | Latency | Throughput | Complexity | |---------|----------|---------|------------|------------| | Sync REST | Files <60s, low volume | Low | Low | Simple | | Async Queue | Batch, files >60s | Medium | High | Medium | | WebSocket Proxy | Live audio, real-time | Real-time | Medium | Medium | | Hybrid Router | Mixed workloads | Varies | High | High | | Callback | Files >5min, fire-and-forget | N/A | Very High | Low | ## Instructions ### Step 1: Synchronous REST Pattern ```typescript import express from 'express'; import { createClient } from '@deepgram/sdk'; const app = express(); app.use(express.json()); const deepgram = createClient(process.env.DEEPGRAM_API_KEY!); // Direct API call — best for short files (<60s) app.post('/api/transcribe', async (req, res) => { const { url, model = 'nova-3', diarize = false } = req.body; try { const { result, error } = await deepgram.listen.prerecorded.transcribeUrl( { url }, { model, smart_format: true, diarize, utterances: diarize } ); if (error) return res.status(502).json({ error: error.message }); res.json({ transcript: result.results.channels[0].alternatives[0].transcript, confidence: result.results.channels[0].alternatives[0].confidence, duration: result.metadata.duration, request_id: result.metadata.request_id, utterances: diarize ? result.results.utterances : undefined, }); } catch (err: any) { res.status(500).json({ error: err.message }); } }); ``` ### Step 2: Async Queue Pattern (BullMQ) ```typescript import { Queue, Worker, Job } from 'bullmq'; import { createClient } from '@deepgram/sdk'; import Redis from 'ioredis'; const connection = new Redis(process.env.REDIS_URL ?? 'redis://localhost:6379'); // Producer: submit transcription jobs const transcriptionQueue = new Queue('transcription', { connection }); async function submitJob(audioUrl: string, options: Record<string, any> = {}) { const job = await transcriptionQueue.add('transcribe', { audioUrl, model: options.model ?? 'nova-3', diarize: options.diarize ?? false, submittedAt: new Date().toISOString(), }, { attempts: 3, backoff: { type: 'exponential', delay: 5000 }, removeOnComplete: { age: 86400 }, // Keep for 24h }); console.log(`Job submitted: ${job.id}`); return job.id; } // Consumer: process transcription jobs const deepgram = createClient(process.env.DEEPGRAM_API_KEY!); const worker = new Worker('transcription', async (job: Job) => { const { audioUrl, model, diarize } = job.data; console.log(`Processing job ${job.id}: ${audioUrl}`); const { result, error } = await deepgram.listen.prerecorded.transcribeUrl( { url: audioUrl }, { model, smart_format: true, diarize, utterances: diarize } ); if (error) throw new Error(`Deepgram error: ${error.message}`); const output = { transcript: result.results.channels[0].alternatives[0].transcript, confidence: result.results.channels[0].alternatives[0].confidence, duration: result.metadata.duration, request_id: result.metadata.request_id, }; // Store result (database, S3, etc.) console.log(`Job ${job.id} complete: ${output.duration}s audio`); return output; }, { connection, concurrency: 10, // Process 10 jobs simultaneously limiter: { max: 50, // Max 50 per time window duration: 60000, // Per minute }, }); worker.on('completed', (job) => console.log(`Completed: ${job.id}`)); worker.on('failed', (job, err) => console.error(`Failed: ${job?.id}`, err.message)); ``` ### Step 3: WebSocket Proxy for Real-Time ```typescript import { WebSocketServer, WebSocket } from 'ws'; import { createClient, LiveTranscriptionEvents } from '@deepgram/sdk'; const wss = new WebSocketServer({ port: 8080 }); wss.on('connection', (clientWs: WebSocket) => { console.log('Client connected'); const deepgram = createClient(process.env.DEEPGRAM_API_KEY!); const dgConnection = deepgram.listen.live({ model: 'nova-3', smart_format: true, interim_results: true, utterance_end_ms: 1000, encoding: 'linear16', sample_rate: 16000, channels: 1, }); // Forward Deepgram transcripts to client dgConnection.on(LiveTranscriptionEvents.Transcript, (data) => { const transcript = data.channel.alternatives[0]?.transcript; if (transcript && clientW
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__deepgram-reference-architecture.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Deepgram Reference Architecture skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Deepgram Reference Architecture safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Deepgram Reference Architecture access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Deepgram Reference Architecture work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.