Atlas / Skills / jeremylongshore / Klingai Prod Checklist

Klingai Prod ChecklistSAFE

skills/jeremylongshore/klingai-prod-checklist

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
1.18.0
Hosts
1 documented
License
MIT
Stars
2,824
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-09
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: klingai-prod-checklist
description: 'Production readiness checklist for Kling AI integrations. Use before
  going live or during

  deployment review. Trigger with phrases like ''klingai production ready'', ''kling
  ai go live'',

  ''klingai checklist'', ''deploy klingai''.

  '
allowed-tools: Read, Write, Edit, Bash(npm:*), Grep
version: 1.18.0
license: MIT
author: Jeremy Longshore <[email protected]>
tags:
- saas
- kling-ai
- production
- deployment
compatibility: Designed for Claude Code
---
# Kling AI Production Checklist

## Overview

Checklist covering authentication, error handling, cost controls, monitoring, security, and content policy before deploying Kling AI video generation to production.

## Authentication

- [ ] AK/SK stored in secrets manager (not `.env` in repo)
- [ ] JWT auto-refresh with 5-min buffer before 30-min expiry
- [ ] Separate API keys per environment (dev/staging/prod)
- [ ] Key rotation schedule (quarterly minimum)
- [ ] `Authorization: Bearer <token>` format verified

## Error Handling

- [ ] HTTP 400/401/402/403/429/5xx all handled
- [ ] Exponential backoff with jitter for 429/5xx retries
- [ ] Max retry limit set (3-5, not infinite)
- [ ] `task_status: "failed"` logs `task_status_msg`
- [ ] 30s timeout on all HTTP calls
- [ ] `duration` sent as string `"5"` not integer `5`

## Cost Controls

- [ ] Daily credit budget enforced in code
- [ ] Alert at 80% daily budget consumption
- [ ] `standard` mode used for non-final renders
- [ ] Max poll attempts cap (no infinite loops)
- [ ] Credit estimate before batch submission

```python
# Pre-batch credit check
credits_needed = len(prompts) * 10  # 10 credits per 5s standard
if credits_needed > DAILY_BUDGET:
    raise RuntimeError(f"Batch needs {credits_needed}, budget is {DAILY_BUDGET}")
```

## Task Management

- [ ] All task_ids logged with timestamp
- [ ] Stuck task detection (>10 min in processing)
- [ ] `callback_url` used instead of polling in production
- [ ] Failed tasks queued for retry
- [ ] Video URLs downloaded promptly (Kling CDN URLs expire)

## Content Safety

- [ ] Prompts validated before API submission
- [ ] User-generated prompts sanitized
- [ ] Default negative prompt includes safety terms
- [ ] Content moderation on user-facing apps
- [ ] Policy violation errors handled gracefully

## Security

- [ ] API keys never logged (redacted in debug output)
- [ ] Video URLs treated as temporary (store on own CDN)
- [ ] Webhook endpoints HTTPS-only
- [ ] Rate limiting on your API layer
- [ ] No sensitive data in prompt strings

## Monitoring

- [ ] API latency tracked per endpoint
- [ ] Success/failure rate dashboard
- [ ] Credit consumption metrics
- [ ] Alert on >5% failure rate
- [ ] Structured JSON logs for all API calls

## Performance

- [ ] Connection pooling via `requests.Session()`
- [ ] Concurrent tasks within API tier limit
- [ ] Video downloads async/background
- [ ] Generated videos CDN-cached

```python
# Connection pooling
session = requests.Session()
adapter = requests.adapters.HTTPAdapter(pool_connections=5, pool_maxsize=10)
session.mount("https://", adapter)
```

## Pre-Launch Smoke Test

```python
from kling_client import KlingClient

c = KlingClient()
result = c.text_to_video("test: blue sky with clouds", duration=5, mode="standard")
assert result["videos"][0]["url"], "No video URL"
print("READY FOR PRODUCTION")
```

## Prerequisites

- A signed release change, approved production workspace, rights-cleared or synthetic smoke-test brief, policy review, budget ceiling, draft-only canary route, and tested rollback/removal procedure.

## Instructions

1. Run the smoke test in staging first with a synthetic, watermarked draft; reject literal credentials, unapproved sources, or public destinations.
2. Verify health, task completion, policy/rights outcome, credit usage, access scope, retention, and draft-only behavior before production approval.
3. Release one bounded production canary only after owner sign-off; halt and remove outputs on policy, rights, quality, scope, or budget drift.
4. Promote in stages, preserving a redacted receipt and the rollback reference; delete temporary assets at the retention boundary.

## Output

Produce a production receipt with release ID, environment, smoke-test brief classification, aggregate health/task result, policy/rights/budget checks, draft destination, approver, retention/removal proof, and rollback reference. Exclude prompts, asset URLs, and credentials.

## Examples

`release=r31; env=staging; brief=synthetic-smoke; policy=pass; rights=pass; destination=draft-only; approval=pending; rollback=r30` supports canary approval.

## Resources

- [API Reference](https://app.klingai.com/global/dev/document-api/apiReference/model/textToVideo)
- [Content Policy](https://app.klingai.com/global/dev/document-api/protocols/paidServiceProtocol)
- [Developer Portal](https://app.klingai.com/global/dev)
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__klingai-prod-checklist.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-094f83675ca38aSAFEB89first audit
06

Questions

What does the Klingai Prod Checklist skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Klingai Prod Checklist safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Klingai Prod Checklist access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Klingai Prod Checklist work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement