Fathom Upgrade MigrationSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| cursor | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: fathom-upgrade-migration description: 'Handle Fathom API changes and version migrations. Trigger with phrases like "upgrade fathom", "fathom api changes", "fathom migration". ' allowed-tools: Read, Write, Edit, Grep version: 1.6.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - meeting-intelligence - ai-notes - fathom compatibility: Designed for Claude Code --- # Fathom Upgrade & Migration ## Prerequisites - Current/target version inventory, compatibility notes, synthetic fixtures, acceptance criteria, and rollback owner. ## Instructions 1. Inventory configuration, credentials, CRM mappings, access, retention, and consent behavior. 2. Test the target in development/staging with synthetic meetings and records. 3. Compare aggregate quality, delivery, error, access, and policy results before a bounded canary. 4. Pause or roll back on regression and retain the prior configuration until sign-off. ## Output - A staged upgrade record with evidence, owner, observation window, and rollback revision. ## Examples Upgrade the integration in staging, run mock/unit and synthetic workflow checks against prior and target versions, and compare aggregate sync/follow-up behavior. Roll back on consent, access, mapping, or reliability regression; do not replay customer meetings to validate a migration. ## Overview Fathom is an AI meeting assistant that records, transcribes, and summarizes meetings. The API operates under `/external/v1` and exposes endpoints for meetings, transcripts, and action items. Tracking API changes is important because Fathom iterates rapidly on transcript schema fields (speaker attribution, sentiment data, highlight clips) and breaking changes to response shapes can silently corrupt downstream integrations that consume meeting data for CRM sync or analytics pipelines. ## Version Detection ```typescript const FATHOM_BASE = "https://api.fathom.video/external/v1"; interface FathomVersionCheck { apiVersion: string; knownFields: string[]; detectedFields: string[]; newFields: string[]; removedFields: string[]; } async function detectFathomApiChanges(apiKey: string): Promise<FathomVersionCheck> { const res = await fetch(`${FATHOM_BASE}/meetings?limit=1`, { headers: { Authorization: `Bearer ${apiKey}` }, }); const data = await res.json(); const knownFields = ["id", "title", "created_at", "duration", "attendees", "transcript_url"]; const detectedFields = data.meetings?.[0] ? Object.keys(data.meetings[0]) : []; return { apiVersion: res.headers.get("x-api-version") ?? "v1", knownFields, detectedFields, newFields: detectedFields.filter((f) => !knownFields.includes(f)), removedFields: knownFields.filter((f) => !detectedFields.includes(f)), }; } ``` ## Migration Checklist - [ ] Review Fathom product updates for API changes and deprecations - [ ] Audit all endpoints referencing `/external/v1` in codebase - [ ] Verify meeting list response schema matches current field expectations - [ ] Check transcript endpoint for new speaker attribution fields - [ ] Validate action item extraction format (structured vs. plain text) - [ ] Update OAuth token refresh flow if auth endpoints changed - [ ] Test webhook payloads for meeting completion events - [ ] Verify pagination parameters (`cursor` vs. `offset`) are current - [ ] Update CRM sync mappings if meeting metadata fields renamed - [ ] Run integration tests against Fathom sandbox environment ## Schema Migration ```typescript // Fathom transcript response evolved: flat text → speaker-attributed segments interface OldTranscript { meeting_id: string; text: string; created_at: string; } interface NewTranscript { meeting_id: string; segments: Array<{ speaker: string; text: string; start_time: number; end_time: number; confidence: number; }>; summary: string; action_items: Array<{ text: string; assignee?: string }>; created_at: string; } function migrateTranscript(old: OldTranscript): NewTranscript { return { meeting_id: old.meeting_id, segments: [{ speaker: "Unknown", text: old.text, start_time: 0, end_time: 0, confidence: 1.0 }], summary: "", action_items: [], created_at: old.created_at, }; } ``` ## Rollback Strategy ```typescript class FathomClient { private baseUrl: string; private fallbackUrl: string; constructor(private apiKey: string) { this.baseUrl = "https://api.fathom.video/external/v1"; this.fallbackUrl = "https://api.fathom.video/external/v1"; // same base, version in path } async getMeetings(limit = 20): Promise<any> { try { const res = await fetch(`${this.baseUrl}/meetings?limit=${limit}`, { headers: { Authorization: `Bearer ${this.apiKey}` }, }); if (!res.ok) throw new Error(`Fathom API ${res.status}`); return await res.json(); } catch (err) { console.warn("Primary endpoint failed, attempting fallback:", err); const res = await fetch(`${this.fallbackUrl}/meetings?limit=${limit}`, { headers: { Authorization: `Bearer ${this.apiKey}`, Accept: "application/json; version=legacy" }, }); return await res.json(); } } } ``` ## Error Handling | Migration Issue | Symptom | Fix | |----------------|---------|-----| | Transcript schema changed | Missing `segments` array, only flat `text` returned | Update parser to handle both old flat and new segmented formats | | Webhook payload mismatch | `meeting.completed` event missing expected fields | Re-register webhook with updated event schema version | | OAuth scope expansion | `403 Forbidden` on transcript endpoint | Re-authorize with updated scopes (`meetings.read`, `transcripts.read`) | | Pagination cursor invalid | `400 Bad Request` with cursor token | Switch from offset-based to cursor-based pagination if API changed | | Rate limit headers changed | `429` without `Retry-After` header | Implement exponential backoff instead of relying on
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__fathom-upgrade-migration.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Fathom Upgrade Migration skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Fathom Upgrade Migration safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Fathom Upgrade Migration access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Fathom Upgrade Migration work with?
Its documentation mentions claude-code and cursor. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.