Atlas / Skills / jeremylongshore / Gamma Prod Checklist

Gamma Prod ChecklistSAFE

skills/jeremylongshore/gamma-prod-checklist

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
1.13.0
Hosts
1 documented
License
MIT
Stars
2,823
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: gamma-prod-checklist
description: 'Production readiness checklist for Gamma integration.

  Use when preparing to deploy Gamma integration to production,

  or auditing existing production setup.

  Trigger with phrases like "gamma production", "gamma prod ready",

  "gamma go live", "gamma deployment checklist", "gamma launch".

  '
allowed-tools: Read, Write, Edit, Grep
version: 1.13.0
license: MIT
author: Jeremy Longshore <[email protected]>
tags:
- saas
- gamma
- deployment
- golang
- audit
compatibility: Designed for Claude Code
---
# Gamma Production Checklist

## Instructions

Attach evidence or an owner decision to each control, run a fictional-content canary, verify publishing/visibility/privacy and rollback behavior, and stop promotion on an access, destination, or health failure.

## Output

Create a go-live receipt with completed controls, aggregate canary results, approver, exceptions, rollback owner, and follow-up date. Exclude private content, viewer data, and credentials.

## Error Handling

Pause publishing and integrations on policy failures, restore the prior configuration, and keep only redacted incident evidence.

## Examples

Publish a fictional staging deck, revoke a test viewer, and simulate a failed integration. Promote only after the owner records that access and rollback worked correctly.

## Overview

Comprehensive checklist to ensure your Gamma integration is production-ready.

## Prerequisites

- Completed development and testing
- Staging environment validated
- Monitoring infrastructure ready

## Production Checklist

### 1. Authentication & Security

- [ ] Production API key obtained (not development key)
- [ ] API key stored in secret manager (not env file)
- [ ] Key rotation procedure documented and tested
- [ ] Minimum required scopes configured
- [ ] No secrets in source code or logs

```typescript
// Production client configuration
const gamma = new GammaClient({
  apiKey: await secretManager.getSecret('GAMMA_API_KEY'),
  timeout: 30000,  # 30000: 30 seconds in ms
  retries: 3,
});
```

### 2. Error Handling

- [ ] All API calls wrapped in try/catch
- [ ] Exponential backoff for rate limits
- [ ] Graceful degradation for API outages
- [ ] User-friendly error messages
- [ ] Error tracking integration (Sentry, etc.)

```typescript
import * as Sentry from '@sentry/node';

try {
  await gamma.presentations.create({ ... });
} catch (err) {
  Sentry.captureException(err, {
    tags: { service: 'gamma', operation: 'create' },
  });
  throw new UserError('Unable to create presentation. Please try again.');
}
```

### 3. Performance

- [ ] Client instance reused (singleton pattern)
- [ ] Connection pooling enabled
- [ ] Appropriate timeouts configured
- [ ] Response caching where applicable
- [ ] Async operations for long tasks

### 4. Monitoring & Logging

- [ ] Request/response logging (sanitized)
- [ ] Latency metrics collection
- [ ] Error rate alerting
- [ ] Rate limit monitoring
- [ ] Health check endpoint

```typescript
// Health check
app.get('/health/gamma', async (req, res) => {
  try {
    await gamma.ping();
    res.json({ status: 'healthy', service: 'gamma' });
  } catch (err) {
    res.status(503).json({ status: 'unhealthy', error: err.message });  # HTTP 503 Service Unavailable
  }
});
```

### 5. Rate Limiting

- [ ] Rate limit tier confirmed with Gamma
- [ ] Request queuing implemented
- [ ] Backoff strategy in place
- [ ] Usage monitoring alerts
- [ ] Burst protection enabled

### 6. Data Handling

- [ ] PII handling compliant with policies
- [ ] Data retention policies documented
- [ ] Export data properly secured
- [ ] User consent for AI processing
- [ ] GDPR/CCPA compliance verified

### 7. Disaster Recovery

- [ ] Fallback behavior defined
- [ ] Circuit breaker implemented
- [ ] Recovery procedures documented
- [ ] Backup API key available
- [ ] Incident response plan ready

```typescript
import CircuitBreaker from 'opossum';

const breaker = new CircuitBreaker(
  (opts) => gamma.presentations.create(opts),
  {
    timeout: 30000,  # 30000: 30 seconds in ms
    errorThresholdPercentage: 50,
    resetTimeout: 30000,  # 30 seconds in ms
  }
);

breaker.fallback(() => ({
  error: 'Service temporarily unavailable',
  retry: true,
}));
```

### 8. Testing

- [ ] Integration tests passing
- [ ] Load testing completed
- [ ] Failure scenario testing done
- [ ] API mock for CI/CD
- [ ] Staging environment validated

### 9. Documentation

- [ ] API integration documented
- [ ] Runbooks for common issues
- [ ] Architecture diagrams updated
- [ ] On-call procedures defined
- [ ] Team trained on Gamma features

## Final Verification Script

```text
#!/bin/bash
set -euo pipefail
# prod-verify.sh

echo "Gamma Production Verification"

# Check API key
if [ -z "$GAMMA_API_KEY" ]; then
  echo "FAIL: GAMMA_API_KEY not set"
  exit 1
fi

# Test connection
curl -s -o /dev/null -w "%{http_code}" \
  -H "Authorization: Bearer $GAMMA_API_KEY" \
  https://api.gamma.app/v1/ping | grep -q "200" \  # HTTP 200 OK
  && echo "OK: API connection" \
  || echo "FAIL: API connection"

echo "Verification complete"
```

## Resources

- [Gamma Production Guide](https://gamma.app/docs/production)
- [Gamma SLA](https://gamma.app/sla)
- [Gamma Status Page](https://status.gamma.app)

## Next Steps

Proceed to `gamma-upgrade-migration` for version upgrades.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__gamma-prod-checklist.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f83675ca38aSAFEB89first audit
06

Questions

What does the Gamma Prod Checklist skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Gamma Prod Checklist safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Gamma Prod Checklist access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Gamma Prod Checklist work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement