Framer Prod ChecklistSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: framer-prod-checklist description: 'Execute Framer production deployment checklist and rollback procedures. Use when deploying Framer integrations to production, preparing for launch, or implementing go-live procedures. Trigger with phrases like "framer production", "deploy framer", "framer go-live", "framer launch checklist". ' allowed-tools: Read, Bash(curl:*), Grep version: 1.5.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - framer compatibility: Designed for Claude Code --- # Framer Production Checklist ## Prerequisites A launch owner, approver, staging evidence with fictional content, domain/DNS owner, access policy, and rollback operator. ## Instructions Attach evidence or an owner decision to every control, validate publishing/domain/integration/privacy behavior in a canary, observe aggregate health, and stop promotion on threshold or access failures. ## Error Handling Pause publishing on domain, access, visitor-data, or integration failures; restore the prior configuration and verify the rollback before resolving the incident. ## Examples Publish a fictional staging page, revoke a test collaborator, and simulate a failed domain check. Promote only after the owner records that access and rollback behaved as expected. ## Overview Checklist for deploying Framer plugins, code components, and Server API integrations to production. ## Checklist ### Plugin Production - [ ] Plugin tested in Framer editor with real data - [ ] No `console.log` calls remaining - [ ] Error states handled (network failures, API errors) - [ ] Loading states shown during async operations - [ ] Plugin UI responsive at configured width/height - [ ] All property controls have default values ### Code Components - [ ] `export default` on all components - [ ] `addPropertyControls` on all components - [ ] Responsive at all viewport sizes - [ ] No hardcoded data (use property controls or CMS) - [ ] Error boundaries for data-fetching components - [ ] Performance tested with large datasets ### Server API (CMS Sync) - [ ] API key in secrets vault (not `.env`) - [ ] CMS collection schema matches source data - [ ] Incremental sync (not full replace every run) - [ ] Error handling with notifications - [ ] Publish step tested - [ ] Rate limiting for batch operations ### Site Publishing - [ ] Custom domain configured - [ ] SEO meta tags on all pages - [ ] CMS collections populated - [ ] Code components rendering correctly in preview - [ ] Code overrides working in published site ## Output - Verified plugin, components, and CMS sync - Production API key secured - Site published and accessible ## Resources - Framer Publishing - Custom Domains ## Next Steps For version upgrades, see `framer-upgrade-migration`.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__framer-prod-checklist.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Framer Prod Checklist skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Framer Prod Checklist safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Framer Prod Checklist access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Framer Prod Checklist work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.