Gamma Prod ChecklistSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: gamma-prod-checklist description: 'Production readiness checklist for Gamma integration. Use when preparing to deploy Gamma integration to production, or auditing existing production setup. Trigger with phrases like "gamma production", "gamma prod ready", "gamma go live", "gamma deployment checklist", "gamma launch". ' allowed-tools: Read, Write, Edit, Grep version: 1.13.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - gamma - deployment - golang - audit compatibility: Designed for Claude Code --- # Gamma Production Checklist ## Instructions Attach evidence or an owner decision to each control, run a fictional-content canary, verify publishing/visibility/privacy and rollback behavior, and stop promotion on an access, destination, or health failure. ## Output Create a go-live receipt with completed controls, aggregate canary results, approver, exceptions, rollback owner, and follow-up date. Exclude private content, viewer data, and credentials. ## Error Handling Pause publishing and integrations on policy failures, restore the prior configuration, and keep only redacted incident evidence. ## Examples Publish a fictional staging deck, revoke a test viewer, and simulate a failed integration. Promote only after the owner records that access and rollback worked correctly. ## Overview Comprehensive checklist to ensure your Gamma integration is production-ready. ## Prerequisites - Completed development and testing - Staging environment validated - Monitoring infrastructure ready ## Production Checklist ### 1. Authentication & Security - [ ] Production API key obtained (not development key) - [ ] API key stored in secret manager (not env file) - [ ] Key rotation procedure documented and tested - [ ] Minimum required scopes configured - [ ] No secrets in source code or logs ```typescript // Production client configuration const gamma = new GammaClient({ apiKey: await secretManager.getSecret('GAMMA_API_KEY'), timeout: 30000, # 30000: 30 seconds in ms retries: 3, }); ``` ### 2. Error Handling - [ ] All API calls wrapped in try/catch - [ ] Exponential backoff for rate limits - [ ] Graceful degradation for API outages - [ ] User-friendly error messages - [ ] Error tracking integration (Sentry, etc.) ```typescript import * as Sentry from '@sentry/node'; try { await gamma.presentations.create({ ... }); } catch (err) { Sentry.captureException(err, { tags: { service: 'gamma', operation: 'create' }, }); throw new UserError('Unable to create presentation. Please try again.'); } ``` ### 3. Performance - [ ] Client instance reused (singleton pattern) - [ ] Connection pooling enabled - [ ] Appropriate timeouts configured - [ ] Response caching where applicable - [ ] Async operations for long tasks ### 4. Monitoring & Logging - [ ] Request/response logging (sanitized) - [ ] Latency metrics collection - [ ] Error rate alerting - [ ] Rate limit monitoring - [ ] Health check endpoint ```typescript // Health check app.get('/health/gamma', async (req, res) => { try { await gamma.ping(); res.json({ status: 'healthy', service: 'gamma' }); } catch (err) { res.status(503).json({ status: 'unhealthy', error: err.message }); # HTTP 503 Service Unavailable } }); ``` ### 5. Rate Limiting - [ ] Rate limit tier confirmed with Gamma - [ ] Request queuing implemented - [ ] Backoff strategy in place - [ ] Usage monitoring alerts - [ ] Burst protection enabled ### 6. Data Handling - [ ] PII handling compliant with policies - [ ] Data retention policies documented - [ ] Export data properly secured - [ ] User consent for AI processing - [ ] GDPR/CCPA compliance verified ### 7. Disaster Recovery - [ ] Fallback behavior defined - [ ] Circuit breaker implemented - [ ] Recovery procedures documented - [ ] Backup API key available - [ ] Incident response plan ready ```typescript import CircuitBreaker from 'opossum'; const breaker = new CircuitBreaker( (opts) => gamma.presentations.create(opts), { timeout: 30000, # 30000: 30 seconds in ms errorThresholdPercentage: 50, resetTimeout: 30000, # 30 seconds in ms } ); breaker.fallback(() => ({ error: 'Service temporarily unavailable', retry: true, })); ``` ### 8. Testing - [ ] Integration tests passing - [ ] Load testing completed - [ ] Failure scenario testing done - [ ] API mock for CI/CD - [ ] Staging environment validated ### 9. Documentation - [ ] API integration documented - [ ] Runbooks for common issues - [ ] Architecture diagrams updated - [ ] On-call procedures defined - [ ] Team trained on Gamma features ## Final Verification Script ```text #!/bin/bash set -euo pipefail # prod-verify.sh echo "Gamma Production Verification" # Check API key if [ -z "$GAMMA_API_KEY" ]; then echo "FAIL: GAMMA_API_KEY not set" exit 1 fi # Test connection curl -s -o /dev/null -w "%{http_code}" \ -H "Authorization: Bearer $GAMMA_API_KEY" \ https://api.gamma.app/v1/ping | grep -q "200" \ # HTTP 200 OK && echo "OK: API connection" \ || echo "FAIL: API connection" echo "Verification complete" ``` ## Resources - [Gamma Production Guide](https://gamma.app/docs/production) - [Gamma SLA](https://gamma.app/sla) - [Gamma Status Page](https://status.gamma.app) ## Next Steps Proceed to `gamma-upgrade-migration` for version upgrades.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__gamma-prod-checklist.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Gamma Prod Checklist skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Gamma Prod Checklist safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Gamma Prod Checklist access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Gamma Prod Checklist work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.