Fathom Ci IntegrationSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: fathom-ci-integration description: 'Test Fathom integrations in CI/CD pipelines. Trigger with phrases like "fathom CI", "fathom github actions", "test fathom pipeline". ' allowed-tools: Read, Write, Edit, Bash(gh:*) version: 1.6.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - meeting-intelligence - ai-notes - fathom compatibility: Designed for Claude Code --- # Fathom CI Integration ## Prerequisites - A protected repository, mocked fixtures, required checks, and a separate scoped development credential for optional integration tests. ## Instructions 1. Run deterministic schema/mapping/template/unit checks on pull requests without credentials. 2. Run live synthetic integration checks only from trusted protected workflows. 3. Bound retries and resources, retain redacted evidence, and keep production deployment approval separate. ## Output - A credential-free PR validation lane and a trusted development integration lane with redacted receipts. ## Examples Run mocked meeting/CRM mapping tests on every pull request, then execute one synthetic protected-branch check using a development secret. If it fails, record opaque IDs/status and back off; never expose Fathom/CRM credentials or real meeting data to forked code. ## Overview Set up CI/CD for Fathom meeting intelligence integrations: run unit tests with mocked transcript and action-item responses on every PR, validate live API connectivity against the Fathom meetings endpoint on merge to main. Fathom provides AI-generated meeting summaries, transcripts, and action items, so CI pipelines focus on verifying data parsing logic and webhook handling for real-time meeting events. ## GitHub Actions Workflow ```yaml # .github/workflows/fathom-ci.yml name: Fathom CI on: pull_request: paths: ['src/fathom/**', 'tests/**'] push: branches: [main] jobs: unit-tests: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: { node-version: '20' } - run: npm ci - run: npm test -- --reporter=verbose integration-tests: if: github.ref == 'refs/heads/main' needs: unit-tests runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: { node-version: '20' } - run: npm ci - run: npm run test:integration env: FATHOM_API_KEY: ${{ secrets.FATHOM_API_KEY }} ``` ## Mock-Based Unit Tests ```typescript // tests/fathom-service.test.ts import { describe, it, expect, vi } from 'vitest'; import { extractActionItems } from '../src/fathom-service'; const mockMeeting = { id: 'mtg_abc123', title: 'Sprint Planning', date: '2026-04-01T10:00:00Z', transcript: 'We need to fix the login bug by Friday...', action_items: [ { assignee: 'Alice', task: 'Fix login bug', due: '2026-04-05' }, { assignee: 'Bob', task: 'Update API docs', due: '2026-04-07' }, ], }; vi.mock('../src/fathom-client', () => ({ FathomClient: vi.fn().mockImplementation(() => ({ getMeeting: vi.fn().mockResolvedValue(mockMeeting), listMeetings: vi.fn().mockResolvedValue({ meetings: [mockMeeting], total: 1 }), })), })); describe('Fathom Service', () => { it('extracts action items from meeting transcript', async () => { const items = await extractActionItems('mtg_abc123'); expect(items).toHaveLength(2); expect(items[0].assignee).toBe('Alice'); }); }); ``` ## Integration Tests ```typescript // tests/integration/fathom.integration.test.ts import { describe, it, expect } from 'vitest'; const hasKey = !!process.env.FATHOM_API_KEY; describe.skipIf(!hasKey)('Fathom Live API', () => { it('lists recent meetings', async () => { const res = await fetch('https://api.fathom.video/v1/meetings?limit=1', { headers: { Authorization: `Bearer ${process.env.FATHOM_API_KEY}` }, }); expect(res.status).toBe(200); const body = await res.json(); expect(body).toHaveProperty('meetings'); }); }); ``` ## Error Handling | CI Issue | Cause | Fix | |----------|-------|-----| | `401 Unauthorized` | Invalid or expired API key | Regenerate key at fathom.video settings | | Empty meetings list | No recordings in account | Create a test meeting or use sandbox account | | Transcript parsing fails | Meeting still processing | Add retry with 30s delay for recent meetings | | Webhook signature mismatch | Wrong signing secret in CI | Verify `FATHOM_WEBHOOK_SECRET` matches dashboard config | | Rate limit (429) | Too many API calls in tests | Add request throttling between test cases | ## Resources - Fathom API Documentation - [GitHub Actions Secrets](https://docs.github.com/en/actions/security-guides/encrypted-secrets) ## Next Steps For deployment, see `fathom-deploy-integration`.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__fathom-ci-integration.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Fathom Ci Integration skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Fathom Ci Integration safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Fathom Ci Integration access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Fathom Ci Integration work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.