Agent skill

Production Readiness Review

by fossasia in fossasia/eventyay-interpretation

A skill your agent uses to evaluate whether VoxBento is ready for production deployment.

Apache-2.0Auto-check passedDevOps & Cloud

Install Production Readiness Review

skills CLI
$ npx skills add fossasia/eventyay-interpretation --skill production-readiness-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install fossasia/eventyay-interpretation production-readiness-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/fossasia/eventyay-interpretation.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/production-readiness-review .claude/skills/production-readiness-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
production-readiness-review
GitHub stars
1.6k
Token cost
~918 tokens
SKILL.md length
394 words
Files
1
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses to evaluate whether VoxBento is ready for production deployment.

  • Works in 5 steps: Admin login + create event + room +… → Open invite link → booth page → Jitsi… → Open listener page → WHEP connects →… → …
  • Evaluate whether VoxBento is ready for production deployment
  • SKILL.md covers Security Hardening, Infrastructure, Observability and Functional Validation, plus 2 more sections
  • Calls uv and node; needs ADMIN_PASSWORD and SECRET_KEY

What it does

Production Readiness Review is an agent skill from fossasia/eventyay-interpretation. Use this skill to evaluate whether VoxBento is ready for production deployment. Combines security, deployment, and operational readiness checks.

Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Deployment. It works with PostgreSQL. The repository describes itself as: A plugin for live interpretation of video streams. The licence is Apache-2.0.

When your agent uses it

  • Evaluate whether VoxBento is ready for production deployment
  • Tasks that involve Deployment

Example prompts

  • “/production-readiness-review”

Requirements

  • Python 3
  • Docker
  • A credential in SECRET_KEY
  • A credential in API_KEY_ENCRYPTION_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Admin login + create event + room + booth + invite token.
  2. Open invite link → booth page → Jitsi iframe loads → mic test works → go live → WHIP connects.
  3. Open listener page → WHEP connects → audio plays.
  4. Open second interpreter tab (backup) → coordinator reassigns → first tab becomes backup.
  5. Transcription enabled → captions appear on listener page.

What it can do on your machine

Read from SKILL.md and the folder at commit 1ca0139. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ADMIN_PASSWORD
    • SECRET_KEY
    • API_KEY_ENCRYPTION_KEY
    • JVB_AUTH_PASSWORD
    • JICOFO_AUTH_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Production Readiness Review loads about 918 tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 394 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~918

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from fossasia/eventyay-interpretation at commit 1ca0139, republished under its Apache-2.0 licence (© fossasia). 394 words, ~918 tokens.

Download SKILL.mdSave it as .claude/skills/production-readiness-review/SKILL.md (or your agent's skills folder).
name
production-readiness-review
description
Use this skill to evaluate whether VoxBento is ready for production deployment. Combines security, deployment, and operational readiness checks.

Skill: Production Readiness Review

Use this skill to evaluate whether VoxBento is ready for production deployment. Combines security, deployment, and operational readiness checks.


Security Hardening

  • SECRET_KEY ≠ change-me (raises no error but is insecure).
  • API_KEY_ENCRYPTION_KEY is set and ≥32 chars (raises RuntimeError if default).
  • ADMIN_PASSWORD is set (empty = admin login disabled — decide deliberately).
  • DEBUG=false in production settings (portal/config.py debug: bool).
  • TLS termination configured (Caddy via Caddyfile or nginx).
  • Strict-Transport-Security header set by reverse proxy.
  • secure=True on session cookies when served over HTTPS (reverse proxy may handle this via X-Forwarded-Proto).
  • JVB_AUTH_PASSWORD and JICOFO_AUTH_PASSWORD changed from changeme.
  • Rate limiting on /login and /register (see TD-08 — NOT YET IMPLEMENTED).

Infrastructure

  • DATABASE_URL is PostgreSQL (postgresql+asyncpg://...), not SQLite.
  • Database is backed up (automated snapshots).
  • portal-data volume is NOT used (SQLite), or DB is external PostgreSQL.
  • MEDIAMTX_WHIP_BASE is the public HTTPS URL, not localhost.
  • DOCKER_HOST_ADDRESS is set to host's public/LAN IP (required for JVB ICE candidates).
  • MediaMTX UDP ICE port (8189) is open and reachable from browser clients.
  • JVB UDP port (10000) is open for Jitsi media.

Observability

  • Portal logs are captured and retained (Docker logging driver or external).
  • /healthz endpoint monitored (returns mediamtx_ok: true).
  • Alerting on portal restart or MediaMTX unreachability.
  • Transcription worker failure logging monitored (portal logs).

Functional Validation

Run the full test suite:

bash
uv sync --python 3.13 --dev
uv run pytest tests/ -v
node --check static/js/interpreter-booth.js
node --check static/js/whep-listener.js
uv run alembic upgrade head

Manual browser check:

  1. Admin login + create event + room + booth + invite token.
  2. Open invite link → booth page → Jitsi iframe loads → mic test works → go live → WHIP connects.
  3. Open listener page → WHEP connects → audio plays.
  4. Open second interpreter tab (backup) → coordinator reassigns → first tab becomes backup.
  5. Transcription enabled → captions appear on listener page.

Show full SKILL.md (129 more words)Show less

Known Production Gaps (from TECHNICAL_DEBT_REPORT.md)

ItemImpactStatus
In-memory booth state lost on restartActive sessions dropped on deployNot fixed — deploy in low-traffic window
No rate limiting on /loginBrute-force riskNot fixed
No CSRF on admin formsLow risk with lax cookiesNot fixed
Single shared ADMIN_PASSWORDWeaker than per-user adminPartially mitigated by is_admin user flag
_created_paths cache not invalidated on MTX restartWHIP may failMitigated by PATCH fallback

Capacity Planning

ComponentLimitation
Transcription workersMAX_TOTAL_WORKERS = 10 — hard limit
Booth stateSingle-process; no horizontal scaling
MediaMTX streamsOne per language channel; limited by server resources
Jitsi participantsLimited by JVB server capacity
DB connectionsSQLAlchemy async pool (default settings)

For events with >10 simultaneous transcribed booths: increase MAX_TOTAL_WORKERS in worker.py or add a settings override.

© fossasia, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/production-readiness-review of fossasia/eventyay-interpretation.

Open the folder on GitHubat commit 1ca0139

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in fossasia/eventyay-interpretation, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Production Readiness Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Production Readiness Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Production Readiness Review this skillfossasia/eventyay-interpretation1.6k—~918Automated safety check: PassApache-2.0
Mz Release SignoffMaterializeInc/materialize6.4k—~7.2kAutomated safety check: PassCustom licence
Monstermq Broker Configvogler75/monster-mq143—~2.2kAutomated safety check: PassGPL-3.0
Docker Deploymentfossasia/eventyay1.7k—~574Automated safety check: NotesApache-2.0
Deployclacky-ai/openclacky1.2k—~1.9kAutomated safety check: PassMIT
Self-Hosted n8n Deploymentczlonkowski/n8n-skills6.4k—~3.5kAutomated safety check: NotesMIT

Similar skills

  • Mz Release Signoff

    MaterializeInc/materialize

    Verify a release candidate on the Grafana dashboards and sign off in release.

    6.4k GitHub stars~7.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Monstermq Broker Config

    vogler75/monster-mq

    Guide for configuring, deploying, and operating the MonsterMQ broker.

    143 GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Docker Deployment

    fossasia/eventyay

    Docker Compose, container services, deployment. An agent skill from fossasia/eventyay.

    1.7k GitHub stars~574 tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Deploy

    clacky-ai/openclacky

    Deploy Rails applications to Railway. An agent skill from clacky-ai/openclacky.

    1.2k GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Self-Hosted n8n Deployment

    czlonkowski/n8n-skills

    Deploys a production n8n instance to a fresh Linux server over SSH with Docker Compose and Caddy HTTPS, in single or queue mode, and covers updates, backups and hardening.

    6.4k GitHub stars~3.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Azure PostgreSQL Flexible Server SDK for .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~4k tokens
    DevOps & CloudAuto-check passed

More from fossasia/eventyay-interpretation

All 38 skills in this repo
  • Git Guardrails Claude Code

    fossasia/eventyay-interpretation

    Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute.

    1.6k GitHub starsUsed in 12 repos~578 tokens
    Auto-check passed
  • Diagnosing Bugs

    fossasia/eventyay-interpretation

    Diagnosis loop for hard bugs and performance regressions. An agent skill from fossasia/eventyay-interpretation.

    1.6k GitHub starsUsed in 32 repos~2.1k tokens
    Auto-check passed
  • Domain Modeling

    fossasia/eventyay-interpretation

    Build and sharpen a project's domain model. An agent skill from fossasia/eventyay-interpretation.

    1.6k GitHub starsUsed in 30 repos~821 tokens
    Auto-check passed
  • Improve

    fossasia/eventyay-interpretation

    Survey any codebase as a senior advisor and produce prioritized, self-contained implementation plans for OTHER models/agents to execute.

    1.6k GitHub starsUsed in 10 repos~3.7k tokens
    Auto-check: warnings
  • Migrate To Shoehorn

    fossasia/eventyay-interpretation

    Migrate test files from as type assertions to @total-typescript/shoehorn.

    1.6k GitHub starsUsed in 12 repos~698 tokens
    Auto-check passed
  • Setup Pre Commit

    fossasia/eventyay-interpretation

    Set up Husky pre-commit hooks with lint-staged (Prettier), type checking, and tests in the current repo.

    1.6k GitHub starsUsed in 12 repos~565 tokens
    Auto-check passed

Works with

Categories

Questions about Production Readiness Review

What does Production Readiness Review do?

A skill your agent uses to evaluate whether VoxBento is ready for production deployment. Production Readiness Review is an agent skill from fossasia/eventyay-interpretation. Use this skill to evaluate whether VoxBento is ready for production deployment.

When should I use Production Readiness Review?

Production Readiness Review fits situations like: evaluate whether VoxBento is ready for production deployment; tasks that involve Deployment.

How do I install Production Readiness Review in Claude Code?

Run `npx skills add fossasia/eventyay-interpretation --skill production-readiness-review -a claude-code`. Or copy the skill folder (.agents/skills/production-readiness-review in fossasia/eventyay-interpretation) into .claude/skills/production-readiness-review in your project. Claude Code loads it when a task matches its description.

How do I install Production Readiness Review in Codex?

Run `npx skills add fossasia/eventyay-interpretation --skill production-readiness-review -a codex`. Or copy the skill folder (.agents/skills/production-readiness-review in fossasia/eventyay-interpretation) into .agents/skills/production-readiness-review in your project. Codex loads it when a task matches its description.

Can I use Production Readiness Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fossasia/eventyay-interpretation --skill production-readiness-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/production-readiness-review, .gemini/skills/production-readiness-review, .github/skills/production-readiness-review and .opencode/skills/production-readiness-review in your project.

What does Production Readiness Review need to run?

Going by SKILL.md and its folder, Production Readiness Review needs the command-line tools its instructions call (uv and node) and credentials named ADMIN_PASSWORD, SECRET_KEY, API_KEY_ENCRYPTION_KEY and JVB_AUTH_PASSWORD. Our summary lists: Python 3; Docker; A credential in SECRET_KEY; A credential in API_KEY_ENCRYPTION_KEY.

Does Production Readiness Review access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Production Readiness Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Production Readiness Review use?

Production Readiness Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Production Readiness Review use?

About 918 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Production Readiness Review?

Skills that share tags, products or a category with Production Readiness Review: Mz Release Signoff (MaterializeInc/materialize, 6.4k stars), Monstermq Broker Config (vogler75/monster-mq, 143 stars), Docker Deployment (fossasia/eventyay, 1.7k stars) and Deploy (clacky-ai/openclacky, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Production Readiness Review?

fossasia (a GitHub organization) maintains it in fossasia/eventyay-interpretation, which has 1,551 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 5, 2026.

Source: fossasia/eventyay-interpretation on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.