Documenso ObservabilitySAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: documenso-observability description: 'Implement monitoring, logging, and tracing for Documenso integrations. Use when setting up observability, implementing metrics collection, or debugging production issues. Trigger with phrases like "documenso monitoring", "documenso metrics", "documenso logging", "documenso tracing", "documenso observability". ' allowed-tools: Read, Write, Edit version: 1.14.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - documenso - monitoring - observability - debugging compatibility: Designed for Claude Code --- # Documenso Observability ## Output - Redacted, bounded metrics/traces for document lifecycle, signing state, errors, latency, and rate headroom. - An owned alert/runbook path that protects signer identity, document content, and credentials. ## Examples Emit aggregate counts by environment, document state, and status class while excluding document bodies, signer email, signing URLs, IP addresses, tokens, and audit payloads. Trigger a development signing-state alert with a synthetic document, verify the on-call route, then retain only the redacted receipt. ## Overview Implement monitoring, structured logging, and health checks for Documenso integrations. Since Documenso does not expose rate limit headers or usage metrics via API, observability is built around your API call patterns, latency, error rates, and webhook delivery. ## Prerequisites - Working Documenso integration - Monitoring stack (Prometheus/Grafana, Datadog, or CloudWatch) - Logging infrastructure ## Instructions ### Step 1: Instrumented Client Wrapper ```typescript // src/observability/documenso-metrics.ts import { Documenso } from "@documenso/sdk-typescript"; interface Metrics { requestCount: number; errorCount: number; totalLatencyMs: number; errorsByStatus: Record<number, number>; } const metrics: Metrics = { requestCount: 0, errorCount: 0, totalLatencyMs: 0, errorsByStatus: {}, }; export function createInstrumentedClient(): Documenso { const client = new Documenso({ apiKey: process.env.DOCUMENSO_API_KEY! }); return new Proxy(client, { get(target, prop) { const value = (target as any)[prop]; if (typeof value === "object" && value !== null) { return new Proxy(value, { get(innerTarget, method) { const fn = (innerTarget as any)[method]; if (typeof fn !== "function") return fn; return async (...args: any[]) => { const start = Date.now(); metrics.requestCount++; try { const result = await fn.apply(innerTarget, args); metrics.totalLatencyMs += Date.now() - start; return result; } catch (err: any) { metrics.errorCount++; const status = err.statusCode ?? 0; metrics.errorsByStatus[status] = (metrics.errorsByStatus[status] || 0) + 1; metrics.totalLatencyMs += Date.now() - start; throw err; } }; }, }); } return value; }, }); } // Expose metrics for Prometheus scraping export function getMetrics() { return { ...metrics, avgLatencyMs: metrics.requestCount > 0 ? Math.round(metrics.totalLatencyMs / metrics.requestCount) : 0, errorRate: metrics.requestCount > 0 ? (metrics.errorCount / metrics.requestCount * 100).toFixed(2) + "%" : "0%", }; } ``` ### Step 2: Structured Logging ```typescript // src/observability/logger.ts import { createLogger, format, transports } from "winston"; const logger = createLogger({ level: process.env.LOG_LEVEL ?? "info", format: format.combine( format.timestamp(), format.json() ), defaultMeta: { service: "documenso-integration" }, transports: [ new transports.Console(), // Add file or cloud transport for production ], }); // Log Documenso operations with structured context export function logDocumensoOperation( operation: string, documentId?: number, extra?: Record<string, any> ) { logger.info("documenso_operation", { operation, documentId, ...extra, }); } // Log errors with full context export function logDocumensoError( operation: string, error: any, documentId?: number ) { logger.error("documenso_error", { operation, documentId, statusCode: error.statusCode, message: error.message, // Never log API keys }); } ``` ### Step 3: Health Check Endpoint ```typescript // src/api/health.ts import { Documenso } from "@documenso/sdk-typescript"; interface HealthStatus { status: "healthy" | "degraded" | "unhealthy"; latencyMs: number; message: string; } async function checkDocumensoHealth(): Promise<HealthStatus> { const client = new Documenso({ apiKey: process.env.DOCUMENSO_API_KEY! }); const start = Date.now(); try { await client.documents.findV0({ page: 1, perPage: 1 }); const latencyMs = Date.now() - start; if (latencyMs > 5000) { return { status: "degraded", latencyMs, message: "High latency" }; } return { status: "healthy", latencyMs, message: "OK" }; } catch (err: any) { return { status: "unhealthy", latencyMs: Date.now() - start, message: `${err.statusCode ?? "unknown"}: ${err.message}`, }; } } // Express endpoint app.get("/health/documenso", async (req, res) => { const health = await checkDocumensoHealth(); const httpStatus = health.status === "healthy" ? 200 : health.status === "degraded" ? 200 : 503; res.status(httpStatus).json(health); }); ``` ### Step 4: Prometheus Metrics Endpoint ```typescript // src/api/metrics.ts import { getMetrics } from "../observability/documenso-metrics"; app.get("/metrics/documenso", (req, res) => { const m = getMetrics(); res.type("text/plain").send(` # HELP documenso_requests_total Total API requests # TYPE documenso_requests_total
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__documenso-observability.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Documenso Observability skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Documenso Observability safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Documenso Observability access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Documenso Observability work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.