Gamma Data HandlingSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: gamma-data-handling description: 'Handle data privacy, retention, and compliance for Gamma integrations. Use when implementing GDPR compliance, data retention policies, or managing user data within Gamma workflows. Trigger with phrases like "gamma data", "gamma privacy", "gamma GDPR", "gamma data retention", "gamma compliance". ' allowed-tools: Read, Write, Edit version: 1.13.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - gamma - workflow - compliance compatibility: Designed for Claude Code --- # Gamma Data Handling ## Output Record source reference, approved field/destination policy, retention rule, aggregate validation result, owner, and exception state. Keep presentation content, viewer data, and credentials outside the receipt. ## Examples Process a fictional staging deck through a field allowlist, confirm only approved metadata reaches the test destination, and remove the fixture according to the retention policy. ## Overview Data handling, privacy controls, and compliance for Gamma API integrations. Gamma processes user-submitted content through AI to generate presentations -- understand what data flows where and how to handle PII, retention, and GDPR requirements. ## Prerequisites - Understanding of data privacy regulations (GDPR, CCPA) - Completed `gamma-install-auth` setup - Data classification policies defined ## Data Flow Map ``` User Input (content, prompts) │ ▼ ┌──────────────┐ │ Your App │ ← PII may be in content (names, company data) │ (API key) │ └──────┬───────┘ │ POST /v1.0/generations ▼ ┌──────────────┐ │ Gamma API │ ← Content processed by AI │ (gamma.app) │ ← Images generated └──────┬───────┘ │ gammaUrl + exportUrl ▼ ┌──────────────┐ │ Generated │ ← Presentation stored in Gamma workspace │ Content │ ← Export files (PDF/PPTX/PNG) temporary └──────────────┘ ``` ## Data Classification | Data Type | Classification | Where Stored | Retention | |-----------|---------------|--------------|-----------| | API key | Secret | Your env vars | Active use only | | Content/prompts | May contain PII | Gamma servers (during generation) | Gamma's policy | | Generated gammas | User data | Gamma workspace | User-controlled | | Export files (PDF/PPTX) | User data | Temporary URLs | Download promptly, URLs expire | | User prompts in logs | PII risk | Your infrastructure | Your policy (sanitize!) | | Credit usage | Billing data | Gamma | Per Gamma ToS | ## Instructions ### Step 1: Sanitize Content Before Sending ```typescript // src/gamma/sanitize.ts // Remove PII from content before sending to Gamma if not needed interface SanitizeOptions { removeEmails: boolean; removePhones: boolean; maskNames: boolean; } function sanitizeContent(content: string, opts: SanitizeOptions): string { let sanitized = content; if (opts.removeEmails) { sanitized = sanitized.replace(/[\w.-]+@[\w.-]+\.\w+/g, "[email]"); } if (opts.removePhones) { sanitized = sanitized.replace(/\+?[\d\s()-]{10,}/g, "[phone]"); } if (opts.maskNames) { // Only mask if you have a list of known names // Generic regex would be too aggressive } return sanitized; } // Usage: sanitize before generation const safeContent = sanitizeContent(userContent, { removeEmails: true, removePhones: true, maskNames: false, }); await gamma.generate({ content: safeContent, outputFormat: "presentation", }); ``` ### Step 2: Sanitize Logs ```typescript // src/gamma/logging.ts // Never log raw content or API keys function logGeneration(request: any, result: any) { console.log(JSON.stringify({ event: "gamma_generation", timestamp: new Date().toISOString(), generationId: result.generationId, outputFormat: request.outputFormat, contentLength: request.content?.length, // NEVER log: content (may have PII), apiKey status: result.status, creditsUsed: result.creditsUsed, })); } ``` ### Step 3: Export File Handling ```typescript // src/gamma/exports.ts // Export URLs are temporary — download and store securely import { writeFile } from "node:fs/promises"; import { S3Client, PutObjectCommand } from "@aws-sdk/client-s3"; async function archiveExport( exportUrl: string, metadata: { generationId: string; userId: string } ) { // Download immediately — URLs expire const res = await fetch(exportUrl); if (!res.ok) throw new Error(`Export download failed: ${res.status}`); const buffer = Buffer.from(await res.arrayBuffer()); // Store with encryption const s3 = new S3Client({ region: "us-east-1" }); const key = `gamma-exports/${metadata.userId}/${metadata.generationId}.pdf`; await s3.send(new PutObjectCommand({ Bucket: process.env.EXPORTS_BUCKET!, Key: key, Body: buffer, ContentType: "application/pdf", ServerSideEncryption: "aws:kms", Metadata: { generationId: metadata.generationId, archivedAt: new Date().toISOString(), }, })); console.log(`Archived: s3://${process.env.EXPORTS_BUCKET}/${key}`); } ``` ### Step 4: Data Retention Policy ```typescript // src/gamma/retention.ts interface RetentionPolicy { exportMaxDays: number; // Delete local export copies logRetentionDays: number; // Anonymize generation logs promptRetentionDays: number; // Delete stored prompts } const POLICY: RetentionPolicy = { exportMaxDays: 90, // Keep exports 90 days logRetentionDays: 30, // Anonymize logs after 30 days promptRetentionDays: 7, // Delete prompts after 7 days }; async function enforceRetention() { const cutoff = new Date(); // Delete old exports from S3 cutoff.setDate(cutoff.getDate() - POLICY.exportMaxDays); await deleteOldExports(cutoff); // Anonymize old logs cutoff.setDate(cutoff.getDate() + POLICY.exportMaxDays - POLICY.logRetentionDays); await anonymizeLogs(cutoff); // Delete stored prompts cutoff.setDate(cutoff.getDate() + POLICY.logRetenti
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__gamma-data-handling.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Gamma Data Handling skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Gamma Data Handling safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Gamma Data Handling access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Gamma Data Handling work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.