Documenso Core Workflow ASAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: documenso-core-workflow-a description: 'Implement Documenso document creation and recipient management workflows. Use when creating documents, managing recipients, adding signature fields, or building signing workflows with Documenso. Trigger with phrases like "documenso document", "create document", "add recipient", "documenso signer", "signature field". ' allowed-tools: Read, Write, Edit version: 1.14.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - documenso - workflow compatibility: Designed for Claude Code --- # Documenso Core Workflow A: Document Creation & Recipients ## Output - A role-limited document/recipient workflow with validated metadata, lifecycle, authorization, and redacted audit result. - A safe disable/rollback path for an incorrect recipient, permission, or state transition. ## Examples Create a synthetic development document, assign a test recipient with the minimum required role, verify expiration/authentication/callback behavior, and archive it after the check. If role or recipient behavior is wrong, disable the workflow and correct it before promotion; do not substitute a real signer for the test. ## Overview Complete workflow for creating documents, managing recipients with different roles, positioning fields, and controlling signing order. Covers both the SDK and v1 REST API for document-centric operations. ## Prerequisites - Completed `documenso-install-auth` setup - Understanding of `documenso-sdk-patterns` - PDF file ready for signing ## Instructions ### Step 1: Create a Document with the SDK ```typescript import { Documenso } from "@documenso/sdk-typescript"; import { readFileSync } from "fs"; const client = new Documenso({ apiKey: process.env.DOCUMENSO_API_KEY! }); // Create document shell const doc = await client.documents.createV0({ title: "Service Agreement — Q1 2026", }); // Upload PDF const pdf = readFileSync("./contracts/service-agreement.pdf"); await client.documents.setFileV0(doc.documentId, { file: new Blob([pdf], { type: "application/pdf" }), }); ``` ### Step 2: Recipient Roles Documenso supports these recipient roles: | Role | Behavior | |------|----------| | `SIGNER` | Must complete all assigned fields to finish | | `VIEWER` | Receives a copy but takes no action | | `APPROVER` | Must approve before signers can proceed | | `CC` | Receives a completed copy after all signatures | ```typescript // Add multiple recipients with roles const signer = await client.documentsRecipients.createV0(doc.documentId, { email: "[email protected]", name: "Alice CEO", role: "SIGNER", }); const approver = await client.documentsRecipients.createV0(doc.documentId, { email: "[email protected]", name: "Legal Team", role: "APPROVER", }); const cc = await client.documentsRecipients.createV0(doc.documentId, { email: "[email protected]", name: "Records", role: "CC", }); ``` ### Step 3: Signing Order Control the sequence in which recipients act. Lower numbers go first. ```typescript // Sequential signing: legal approves, then CEO signs await client.documentsRecipients.createV0(doc.documentId, { email: "[email protected]", name: "Legal", role: "APPROVER", signingOrder: 1, // Goes first }); await client.documentsRecipients.createV0(doc.documentId, { email: "[email protected]", name: "CEO", role: "SIGNER", signingOrder: 2, // Goes after legal approves }); ``` ### Step 4: Add Fields to Document Field coordinates use **percentage-based positioning** (0-100 for both X and Y axes). The origin is the top-left corner of the page. ```typescript // Signature field — bottom of page 1 await client.documentsFields.createV0(doc.documentId, { recipientId: signer.recipientId, type: "SIGNATURE", pageNumber: 1, pageX: 10, // 10% from left pageY: 85, // 85% from top pageWidth: 30, // 30% of page width pageHeight: 5, // 5% of page height }); // Date field — next to signature await client.documentsFields.createV0(doc.documentId, { recipientId: signer.recipientId, type: "DATE", pageNumber: 1, pageX: 60, pageY: 85, pageWidth: 20, pageHeight: 3, }); // Name field — auto-filled from recipient await client.documentsFields.createV0(doc.documentId, { recipientId: signer.recipientId, type: "NAME", pageNumber: 1, pageX: 10, pageY: 78, pageWidth: 30, pageHeight: 3, }); // Text field — custom input (e.g., title/position) await client.documentsFields.createV0(doc.documentId, { recipientId: signer.recipientId, type: "TEXT", pageNumber: 1, pageX: 60, pageY: 78, pageWidth: 30, pageHeight: 3, }); ``` ### Step 5: Multi-Page Document with Multiple Signers ```typescript async function createMultiSignerContract( pdfPath: string, signers: Array<{ email: string; name: string; signPage: number }> ) { const client = new Documenso({ apiKey: process.env.DOCUMENSO_API_KEY! }); const doc = await client.documents.createV0({ title: "Multi-Party Agreement" }); const pdf = readFileSync(pdfPath); await client.documents.setFileV0(doc.documentId, { file: new Blob([pdf], { type: "application/pdf" }), }); for (let i = 0; i < signers.length; i++) { const s = signers[i]; const recip = await client.documentsRecipients.createV0(doc.documentId, { email: s.email, name: s.name, role: "SIGNER", signingOrder: i + 1, }); // Each signer gets signature + date on their assigned page await client.documentsFields.createV0(doc.documentId, { recipientId: recip.recipientId, type: "SIGNATURE", pageNumber: s.signPage, pageX: 10, pageY: 80, pageWidth: 30, pageHeight: 5, }); await client.documentsFields.createV0(doc.documentId, { recipientId: recip.recipientId, type: "DATE", pageNumber: s.signPage, pageX: 60, pageY: 80, pageWidth: 20, pageHeight: 3, }); } await client.documents.sendV0(doc.documentId); return doc.documentId; } ``` ### Step 6: Docum
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__documenso-core-workflow-a.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Documenso Core Workflow A skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Documenso Core Workflow A safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Documenso Core Workflow A access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Documenso Core Workflow A work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.