Gamma Security BasicsCAUTION
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: gamma-security-basics description: 'Implement security best practices for Gamma integration. Use when securing API keys, implementing access controls, or auditing Gamma security configuration. Trigger with phrases like "gamma security", "gamma API key security", "gamma secure", "gamma credentials", "gamma access control". ' allowed-tools: Read, Write, Edit, Grep version: 1.13.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - gamma - api - security - audit compatibility: Designed for Claude Code --- # Gamma Security Basics ## Output Maintain a security receipt with identity scope, secret reference, access-review date, control result, owner, and redacted incident state. Do not include tokens or private content. ## Examples Use a scoped staging credential and fictional deck to verify least-privilege access, revoke it, and confirm access is denied without exposing content or credentials in evidence. ## Overview Security best practices for Gamma API integration to protect credentials and data. ## Prerequisites - Active Gamma integration - Environment variable support - Understanding of secret management ## Instructions ### Step 1: Secure API Key Storage ```typescript // NEVER do this const gamma = new GammaClient({ apiKey: 'gamma_live_abc123...', // Hardcoded - BAD! }); // DO this instead const gamma = new GammaClient({ apiKey: process.env.GAMMA_API_KEY, }); ``` **Environment Setup:** ```bash # .env (add to .gitignore!) GAMMA_API_KEY=gamma_live_abc123... # Load in application import 'dotenv/config'; ``` ### Step 2: Key Rotation Strategy ```typescript // Support multiple keys for rotation const gamma = new GammaClient({ apiKey: process.env.GAMMA_API_KEY_PRIMARY || process.env.GAMMA_API_KEY_SECONDARY, }); // Rotation script async function rotateApiKey() { // 1. Generate new key in Gamma dashboard // 2. Update GAMMA_API_KEY_SECONDARY // 3. Deploy and verify // 4. Swap PRIMARY and SECONDARY // 5. Revoke old key } ``` ### Step 3: Request Signing (if supported) ```typescript import crypto from 'crypto'; function signRequest(payload: object, secret: string): string { const timestamp = Date.now().toString(); const message = timestamp + JSON.stringify(payload); return crypto .createHmac('sha256', secret) .update(message) .digest('hex'); } // Usage with webhook verification function verifyWebhook(body: string, signature: string, secret: string): boolean { const expected = crypto .createHmac('sha256', secret) .update(body) .digest('hex'); return crypto.timingSafeEqual( Buffer.from(signature), Buffer.from(expected) ); } ``` ### Step 4: Access Control Patterns ```typescript // Scoped API keys (if supported) const readOnlyGamma = new GammaClient({ apiKey: process.env.GAMMA_API_KEY_READONLY, scopes: ['presentations:read', 'exports:read'], }); const fullAccessGamma = new GammaClient({ apiKey: process.env.GAMMA_API_KEY_FULL, }); // Permission check before operations async function createPresentation(user: User, data: object) { if (!user.permissions.includes('gamma:create')) { throw new Error('Insufficient permissions'); } return fullAccessGamma.presentations.create(data); } ``` ### Step 5: Audit Logging ```typescript import { GammaClient } from '@gamma/sdk'; function createAuditedClient(userId: string) { return new GammaClient({ apiKey: process.env.GAMMA_API_KEY, interceptors: { request: (config) => { console.log(JSON.stringify({ timestamp: new Date().toISOString(), userId, action: `${config.method} ${config.path}`, type: 'gamma_api_request', })); return config; }, }, }); } ``` ## Security Checklist - [ ] API keys stored in environment variables - [ ] .env files in .gitignore - [ ] No keys in source code or logs - [ ] Key rotation procedure documented - [ ] Minimal permission scopes used - [ ] Audit logging enabled - [ ] Webhook signatures verified - [ ] HTTPS enforced for all calls ## Error Handling | Security Issue | Detection | Remediation | |----------------|-----------|-------------| | Exposed key | GitHub scanning | Rotate immediately | | Key in logs | Log audit | Filter sensitive data | | Unauthorized access | Audit logs | Revoke and investigate | | Weak permissions | Access review | Apply least privilege | ## Resources - [Gamma Security Guide](https://gamma.app/docs/security) - [API Key Management](https://gamma.app/docs/api-keys) - [OWASP API Security](https://owasp.org/API-Security/) ## Next Steps Proceed to `gamma-prod-checklist` for production readiness.
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (2)
Use a scoped staging credential and fictional deck to verify least-privilege access, revoke it, and confirm access is denied without exposing content or credentials in evidence.
apiKey: 'gamma_live_abc123...', // Hardcoded - BAD!
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__gamma-security-basics.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | CAUTION | B | 89 | first audit |
Questions
What does the Gamma Security Basics skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Gamma Security Basics safe to install?
With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Gamma Security Basics access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Gamma Security Basics work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.