Klingai Prod ChecklistSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-09Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: klingai-prod-checklist description: 'Production readiness checklist for Kling AI integrations. Use before going live or during deployment review. Trigger with phrases like ''klingai production ready'', ''kling ai go live'', ''klingai checklist'', ''deploy klingai''. ' allowed-tools: Read, Write, Edit, Bash(npm:*), Grep version: 1.18.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - kling-ai - production - deployment compatibility: Designed for Claude Code --- # Kling AI Production Checklist ## Overview Checklist covering authentication, error handling, cost controls, monitoring, security, and content policy before deploying Kling AI video generation to production. ## Authentication - [ ] AK/SK stored in secrets manager (not `.env` in repo) - [ ] JWT auto-refresh with 5-min buffer before 30-min expiry - [ ] Separate API keys per environment (dev/staging/prod) - [ ] Key rotation schedule (quarterly minimum) - [ ] `Authorization: Bearer <token>` format verified ## Error Handling - [ ] HTTP 400/401/402/403/429/5xx all handled - [ ] Exponential backoff with jitter for 429/5xx retries - [ ] Max retry limit set (3-5, not infinite) - [ ] `task_status: "failed"` logs `task_status_msg` - [ ] 30s timeout on all HTTP calls - [ ] `duration` sent as string `"5"` not integer `5` ## Cost Controls - [ ] Daily credit budget enforced in code - [ ] Alert at 80% daily budget consumption - [ ] `standard` mode used for non-final renders - [ ] Max poll attempts cap (no infinite loops) - [ ] Credit estimate before batch submission ```python # Pre-batch credit check credits_needed = len(prompts) * 10 # 10 credits per 5s standard if credits_needed > DAILY_BUDGET: raise RuntimeError(f"Batch needs {credits_needed}, budget is {DAILY_BUDGET}") ``` ## Task Management - [ ] All task_ids logged with timestamp - [ ] Stuck task detection (>10 min in processing) - [ ] `callback_url` used instead of polling in production - [ ] Failed tasks queued for retry - [ ] Video URLs downloaded promptly (Kling CDN URLs expire) ## Content Safety - [ ] Prompts validated before API submission - [ ] User-generated prompts sanitized - [ ] Default negative prompt includes safety terms - [ ] Content moderation on user-facing apps - [ ] Policy violation errors handled gracefully ## Security - [ ] API keys never logged (redacted in debug output) - [ ] Video URLs treated as temporary (store on own CDN) - [ ] Webhook endpoints HTTPS-only - [ ] Rate limiting on your API layer - [ ] No sensitive data in prompt strings ## Monitoring - [ ] API latency tracked per endpoint - [ ] Success/failure rate dashboard - [ ] Credit consumption metrics - [ ] Alert on >5% failure rate - [ ] Structured JSON logs for all API calls ## Performance - [ ] Connection pooling via `requests.Session()` - [ ] Concurrent tasks within API tier limit - [ ] Video downloads async/background - [ ] Generated videos CDN-cached ```python # Connection pooling session = requests.Session() adapter = requests.adapters.HTTPAdapter(pool_connections=5, pool_maxsize=10) session.mount("https://", adapter) ``` ## Pre-Launch Smoke Test ```python from kling_client import KlingClient c = KlingClient() result = c.text_to_video("test: blue sky with clouds", duration=5, mode="standard") assert result["videos"][0]["url"], "No video URL" print("READY FOR PRODUCTION") ``` ## Prerequisites - A signed release change, approved production workspace, rights-cleared or synthetic smoke-test brief, policy review, budget ceiling, draft-only canary route, and tested rollback/removal procedure. ## Instructions 1. Run the smoke test in staging first with a synthetic, watermarked draft; reject literal credentials, unapproved sources, or public destinations. 2. Verify health, task completion, policy/rights outcome, credit usage, access scope, retention, and draft-only behavior before production approval. 3. Release one bounded production canary only after owner sign-off; halt and remove outputs on policy, rights, quality, scope, or budget drift. 4. Promote in stages, preserving a redacted receipt and the rollback reference; delete temporary assets at the retention boundary. ## Output Produce a production receipt with release ID, environment, smoke-test brief classification, aggregate health/task result, policy/rights/budget checks, draft destination, approver, retention/removal proof, and rollback reference. Exclude prompts, asset URLs, and credentials. ## Examples `release=r31; env=staging; brief=synthetic-smoke; policy=pass; rights=pass; destination=draft-only; approval=pending; rollback=r30` supports canary approval. ## Resources - [API Reference](https://app.klingai.com/global/dev/document-api/apiReference/model/textToVideo) - [Content Policy](https://app.klingai.com/global/dev/document-api/protocols/paidServiceProtocol) - [Developer Portal](https://app.klingai.com/global/dev)
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__klingai-prod-checklist.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Klingai Prod Checklist skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Klingai Prod Checklist safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Klingai Prod Checklist access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Klingai Prod Checklist work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.