Agent skill

Canva Prod Checklist

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Gate a Canva Connect release on authorization, review eligibility, data controls, async recovery, observability, and rollback evidence.

MITAuto-check passedDevOps & Cloud

Install Canva Prod Checklist

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-prod-checklist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace canva-prod-checklist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/canva-prod-checklist .claude/skills/canva-prod-checklist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
canva-prod-checklist
GitHub stars
2.8k
Token cost
~1k tokens
SKILL.md length
404 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Gate a Canva Connect release on authorization, review eligibility, data controls, async recovery, observability, and rollback evidence.

  • Works in 7 steps: Verify identity and trust → Verify authorization → Verify provider contracts → …
  • Promoting a backend integration
  • SKILL.md covers Overview, Prerequisites, Instructions and Authentication, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Canva Prod Checklist is an agent skill from jeremylongshore/tons-of-skills-marketplace. Gate a Canva Connect release on authorization, review eligibility, data controls, async recovery, observability, and rollback evidence. Use when promoting a backend integration or enabling a new Canva operation. Trigger with: "Canva production checklist", "release Canva integration", "Canva go-live review".

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Requires an exact release artifact, controlled production integration, current feature-status evidence, and rollback authority.

It sits in DevOps & Cloud, covering Observability and Authorization and RBAC. It works with Canva. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Promoting a backend integration
  • Enabling a new Canva operation
  • With: Canva production checklist
  • Release Canva integration

Example prompts

  • “Canva production checklist”
  • “release Canva integration”
  • “Canva go-live review”
  • “/canva-prod-checklist”

Requirements

  • Compatibility (from SKILL.md): Requires an exact release artifact, controlled production integration, current feature-status evidence, and rollback authority.
  • Pre-approved tools (allowed-tools): Read, Grep, Write, Edit

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Verify identity and trust
  2. Verify authorization
  3. Verify provider contracts
  4. Verify operations
  5. Verify data and telemetry
  6. Exercise failure and rollback
  7. Approve or refuse

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • canva.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires an exact release artifact, controlled production integration, current feature-status evidence, and rollback authority.

    From compatibility in the SKILL.md frontmatter.

Context cost

Canva Prod Checklist loads about 1k tokens when it runs, and up to ~1.2k if it reads all its reference files. Until then it costs about 82 tokens; SKILL.md has 404 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 404 words, ~1,027 tokens.

Download SKILL.mdSave it as .claude/skills/canva-prod-checklist/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
canva-prod-checklist
description
Gate a Canva Connect release on authorization, review eligibility, data controls, async recovery, observability, and rollback evidence. Use when promoting a backend integration or enabling a new Canva operation. Trigger with: "Canva production checklist", "release Canva integration", "Canva go-live review".
allowed-tools
Read, Grep, Write, Edit
compatibility
Requires an exact release artifact, controlled production integration, current feature-status evidence, and rollback authority.
version
2.0.0
argument-hint
[release-id-and-environment]
model
inherit
effort
high
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, canva, production, operations

Canva Production Readiness Gate

Overview

Make go-live an evidence decision tied to an immutable artifact. Preview features, broad scopes, unsafe callback hosts, ambiguous jobs, or unverifiable rollback keep the release closed.

Prerequisites

  • Release digest, configuration version, owner, and change scope
  • Production integration, exact redirects, explicit scopes, and feature statuses
  • Test receipts, migrations, observability, data policy, incident plan, and rollback

Instructions

Step 1: Verify identity and trust

Use Read and Grep to confirm exact artifact, environment, integration ID, callback hosts, backend-only secrets, CI event boundaries, and operator ownership.

Step 2: Verify authorization

Review minimum explicit scopes, tenant/resource checks, capabilities, consent changes, disconnect cleanup, and token-refresh serialization.

Step 3: Verify provider contracts

Pin current OpenAPI/changelog, identify deprecated and preview APIs, and confirm public-review eligibility. Canva states public integrations using preview features cannot pass review.

Step 4: Verify operations

Prove operation identity, bounded retry, endpoint/user queueing, async job reconciliation, webhook idempotency if used, and partial-failure cleanup.

Step 5: Verify data and telemetry

Prove content/credential classification, retention/deletion, URL handling, log redaction, low-cardinality metrics, alert ownership, and debug-bundle expiry.

Step 6: Exercise failure and rollback

Use Write or Edit to record mocked failures, protected read-only integration proof, migration recovery, rollback command/path, and post-rollback reconciliation.

Step 7: Approve or refuse

Record exact evidence, approver, residual risks, and activation steps. Refuse if any required fact is inferred rather than proven.

Show full SKILL.md (181 more words)Show less

Authentication

Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.

Tool Discipline

Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.

Output

  • Scoped decision or implementation artifact
  • Redacted operation and validation receipt
  • Failure, rollback, and follow-up ownership record

Examples

A public release using a preview webhook path is refused. The team ships the non-preview core after exact-head tests and keeps the preview feature in a separate non-public experiment.

Error Handling

FailureResponse
Preview status is unclearTreat the feature as ineligible until confirmed
Rollback was not exercisedDo not approve production
Scope set exceeds featuresReduce scopes and obtain new consent where required
Health proof mutates contentReplace it with a protected non-mutating read

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/canva-prod-checklist of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Canva Prod Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Canva Prod Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Canva Prod Checklist this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1kAutomated safety check: PassMIT
Security Sensitive Path InstrumenterArabelaTso/Skills-4-SE253—~1.1kAutomated safety check: PassApache-2.0
KubeSphere Multi-Tenant Managementkubesphere/kubesphere17k—~3.1kAutomated safety check: PassCustom licence
Mirrord Operatormetalbear-co/mirrord5.4k1 repos~4.6kAutomated safety check: PassMIT
Distributed Tracingwshobson/agents40k12 repos~527Automated safety check: PassMIT
Executing Distributed System Testsshenli/distributed-system-testing231—~5.1kAutomated safety check: NotesMIT

Similar skills

  • Instruments authentication, authorization, and input-handling code paths to monitor security-relevant events and states at runtime.

    253 GitHub stars~1.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub stars~3.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Mirrord Operator

    metalbear-co/mirrord

    Help users install and configure the mirrord Operator for team/enterprise environments.

    5.4k GitHub starsUsed in 1 repo~4.6k tokens
    DevOps & CloudAuto-check passed
  • Distributed Tracing

    wshobson/agents

    Implement distributed tracing with Jaeger and Tempo to track requests across microservices and identify performance bottlenecks.

    40k GitHub starsUsed in 12 repos~527 tokens
    DevOps & CloudAuto-check passed
  • Executing Distributed System Tests

    shenli/distributed-system-testing

    A skill your agent uses when running a previously designed distributed-systems test plan against a real or simulated cluster — driving fault injection, workload, chaos scenarios, linearizability /…

    231 GitHub stars~5.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • Reviews and authors Cloudflare Workers code against production best practices.

    127 GitHub starsUsed in 6 repos~1.8k tokens
    DevOps & CloudAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Canva Prod Checklist

What does Canva Prod Checklist do?

Gate a Canva Connect release on authorization, review eligibility, data controls, async recovery, observability, and rollback evidence. Canva Prod Checklist is an agent skill from jeremylongshore/tons-of-skills-marketplace. Gate a Canva Connect release on authorization, review eligibility, data controls, async recovery, observability, and rollback evidence.

When should I use Canva Prod Checklist?

Canva Prod Checklist fits situations like: promoting a backend integration; enabling a new Canva operation; with: Canva production checklist; release Canva integration.

How do I install Canva Prod Checklist in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-prod-checklist -a claude-code`. Or copy the skill folder (skills/.curated/canva-prod-checklist in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/canva-prod-checklist in your project. Claude Code loads it when a task matches its description.

How do I install Canva Prod Checklist in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-prod-checklist -a codex`. Or copy the skill folder (skills/.curated/canva-prod-checklist in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/canva-prod-checklist in your project. Codex loads it when a task matches its description.

Can I use Canva Prod Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-prod-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/canva-prod-checklist, .gemini/skills/canva-prod-checklist, .github/skills/canva-prod-checklist and .opencode/skills/canva-prod-checklist in your project.

What does Canva Prod Checklist need to run?

SKILL.md names no scripts, command-line tools or credentials: Canva Prod Checklist is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Write, Edit. Compatibility (from SKILL.md): Requires an exact release artifact, controlled production integration, current feature-status evidence, and rollback authority..

Does Canva Prod Checklist access the network?

SKILL.md names 1 domain. As links in the text: canva.dev. This is read from the text; nothing was executed.

Is Canva Prod Checklist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Canva Prod Checklist use?

Canva Prod Checklist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Canva Prod Checklist use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 133 tokens, read only when the agent opens those files.

What are the alternatives to Canva Prod Checklist?

Skills that share tags, products or a category with Canva Prod Checklist: Security Sensitive Path Instrumenter (ArabelaTso/Skills-4-SE, 253 stars), KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars), Mirrord Operator (metalbear-co/mirrord, 5.4k stars) and Distributed Tracing (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Canva Prod Checklist?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.