Atlas / Skills / jeremylongshore / Ideogram Deploy Integration

Ideogram Deploy IntegrationBLOCK

skills/jeremylongshore/ideogram-deploy-integration

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
1.11.0
Hosts
1 documented
License
MIT
Stars
2,824
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-09
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: ideogram-deploy-integration
description: >-
  Deploy an Ideogram server boundary with queues, storage, safety enforcement, observability, canaries, and rollback. Use when shipping a new runtime or changing production topology. Trigger with "deploy Ideogram", "ship an Ideogram worker", or "review Ideogram production architecture".
allowed-tools: Read,Glob,Grep,Write,Edit
argument-hint: "<platform> <release-sha> <environment>"
version: 1.11.0
license: MIT
author: Jeremy Longshore <[email protected]>
tags: [saas, ideogram, deployment]
model: inherit
effort: high
compatibility: "Designed for Claude Code; deployment and live generation require explicit approval"
---
# Ideogram Deployment Boundary

## Overview

Deploy Ideogram behind an application-owned server, queue, safety policy, and durable object store. Match runtime deadlines to sync or async behavior, keep paid authority out of clients, and preserve a reversible traffic path.

## Prerequisites

- Frozen release SHA, platform owner, environment, traffic slice, SLO, and rollback target.
- Secret manager, queue or concurrency control, object storage, monitoring, and incident response.
- Positive credit, billing owner, approved synthetic canary, and retention policy.

## Current Contract

Ideogram calls use `https://api.ideogram.ai`; default capacity is 10 in-flight requests. Async routes return `generation_id` and support webhook delivery with polling fallback. Image URLs expire, so deployment must download validated outputs into application storage before acknowledging durable completion.

## Authentication

Inject `IDEOGRAM_API_KEY` into the server or worker identity and send it only as `Api-Key`. A public browser receives application-scoped authorization, never the vendor credential or direct vendor URL.

## Instructions

1. Map request ingress, tenant auth, validation, queue, Ideogram route, webhook, polling, download, safety, storage, and publishing boundaries.
2. Choose sync only when platform and request deadlines safely cover generation plus download; otherwise persist async state.
3. Configure account-level concurrency below verified capacity, bounded queues, retry deadlines, and graceful drain.
4. Inject secrets by runtime reference, restrict egress to the approved host, and prevent request or response body logging.
5. Validate safety and media type before writing an opaque tenant-scoped object; discard temporary URLs.
6. Deploy a synthetic canary, compare status, latency, storage, safety, and cost signals, then increase traffic gradually.
7. Roll back traffic and reconcile in-flight generations and objects before terminating the prior version.

## Tool Discipline

Use Read, Glob, and Grep for manifests, infrastructure, adapters, and evidence. Use Write and Edit only for approved deployment changes. Invocation does not authorize a deploy, secret mutation, credit purchase, traffic shift, or destructive cleanup.

## Approval Boundaries

Require explicit approval for production secret access, new egress, live spend, policy changes, storage retention, traffic shifting, and rollback. Preserve the previous deployable artifact until in-flight work is reconciled.

## Error Handling

- Stop rollout on secret exposure, rising `429`, lost async state, unsafe-publication paths, or storage failure.
- Do not declare success while assets exist only at expiring vendor URLs.
- Drain or cancel local queue work before rollback; reconcile accepted vendor work idempotently.

## Output

Return release SHA, platform, topology, secret reference, concurrency and deadline settings, canary metrics, storage and safety results, traffic state, costs, and rollback receipt. Exclude credentials and content.

## Examples

- Deploy a queue-backed worker for async V4 and a verified webhook receiver with polling reconciliation.
- Keep the old worker at zero new traffic until all known generation IDs reach terminal state.

## Validation

Verify deployed digest, secret provenance, egress, queue bounds, signature checks, polling fallback, storage deletion, dashboards, and rollback. Confirm the canary object and temporary metadata are removed.

## Resources

- [Current first-party evidence map](references/official-docs.md) — use the dated endpoint, webhook, billing, team, and training links as the contract index for this workflow.
- Recheck the endpoint-specific page and current OpenAPI description before relying on an enum, limit, beta feature, or lifecycle claim.
- Record live observations as environment-specific evidence, not as universal vendor guarantees.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
SKILL.md:33
Inject `IDEOGRAM_API_KEY` into the server or worker identity and send it only as `Api-Key`. A public browser receives application-scoped authorization, never the vendor credential or direct vendor URL
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-09 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__ideogram-deploy-integration.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-094f83675ca38aBLOCKD69first audit
06

Questions

What does the Ideogram Deploy Integration skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Ideogram Deploy Integration safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What can Ideogram Deploy Integration access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Ideogram Deploy Integration work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement