Skip to content
Report library
Purpose / Other

Churn Prevention Skill Security Audit

What the author says it does (original text)

When the user wants to reduce churn, build cancellation flows, set up save offers, recover failed payments, or implement retention strategies. Also use when the user mentions 'churn,' 'cancel flow,' 'offboarding,' 'save offer,' 'dunning,' 'failed payment recovery,' 'win-back,' 'retention,' 'exit survey,' 'pause subscription,' 'involuntary churn,' 'people keep canceling,' 'churn rate is too high,'

Independent security check

Do not install or run it yet

Files checked
4
Risks found
4
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Medium risk

Churn prediction centralizes customer behavior and sensitive departure signals

Source references: 4
What we found

The model calls for monitoring logins, feature use, support tickets, email opens, billing-page visits, seat removal, data exports, and NPS, then segmenting by plan, revenue, tenure, usage, and prior offers. This creates customer behavior profiles used for commercial intervention.

Why this matters

Without notice, a lawful basis, access limits, and retention controls, staff or systems could misuse detailed behavior histories. A breach could reveal customers’ business condition, intent to leave, and account value.

The design recommends combining login, feature-use, support, email-open, billing-page, seat-removal, export, and NPS signals, then segmenting by revenue, tenure, usage, and prior offers to drive interventions. This creates detailed behavioral profiles; without notice, a lawful basis, minimization, and retention limits, it can affect privacy and enable differential treatment. Users can require necessary-only collection, purpose and retention limits, and transparency or opt-out for nonessential profiling.

SKILL.md:218In the instructionsOpen original file
|--------|-----------|-----------|| Login frequency drops 50%+ | High | 2-4 weeks before cancel || Key feature usage stops | High | 1-3 weeks before cancel || Support tickets spike then stop | High | 1-2 weeks before cancel || Email open rates decline | Medium | 2-6 weeks before cancel || Billing page visits increase | High | Days before cancel || Team seats removed | High | 1-2 weeks before cancel || Data export initiated | Critical | Days before cancel || NPS score drops below 6 | Medium | 1-3 months before cancel |
Show 3 other places
references/cancel-flow-patterns.md:239In the instructionsOpen original file
| Dimension | Why It Matters ||-----------|---------------|| Plan / MRR | Higher-value customers get personal outreach || Tenure | Long-term customers get more generous offers || Usage level | High-usage customers get different messaging than dormant ones || Billing interval | Monthly vs. annual need different approaches || Previous saves | Don't re-offer the same discount to a repeat canceller || Cancel reason | Drives which offer to show (core mapping) |
SKILL.md:214In the instructionsOpen original file
Track these leading indicators of churn:| Signal | Risk Level | Timeframe ||--------|-----------|-----------|| Login frequency drops 50%+ | High | 2-4 weeks before cancel || Key feature usage stops | High | 1-3 weeks before cancel || Support tickets spike then stop | High | 1-2 weeks before cancel || Email open rates decline | Medium | 2-6 weeks before cancel || Billing page visits increase | High | Days before cancel || Team seats removed | High | 1-2 weeks before cancel || Data export initiated | Critical | Days before cancel || NPS score drops below 6 | Medium | 1-3 months before cancel |
references/cancel-flow-patterns.md:306In the instructionsOpen original file
### GDPR / Data Retention (EU)- Inform users about data retention period post-cancel- Offer data export before account deletion- Honor deletion requests within 30 days- Don't use post-cancel data for marketing without consent
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.Risks found: 1
Medium risk

Passwordless payment-update links are recommended without required link protections

Source references: 1
What we found

The Skill recommends a payment-update link that requires no login where possible, but does not require it to be single-use, short-lived, customer-bound, and narrowly scoped. Passwordless access can be safe, but without those constraints a forwarded, leaked, or guessed link can become an account or billing-data entry point.

Why this matters

An unauthorized holder could potentially view account-related details, alter the payment method, or attach a payment method to the wrong account.

The Skill actively recommends a payment-update link that works without login where possible. If implemented as a long-lived, transferable, or broadly scoped link, anyone obtaining it could access or alter another customer's payment settings. The source does not say whether one-time tokens, short expiry, customer binding, or re-verification protect it, so the actual exposure depends on implementation. Users can require those safeguards and single-customer, single-purpose scope.

SKILL.md:308In the instructionsOpen original file
**Dunning email best practices:**- Direct link to payment update page (no login required if possible)- Show what they'll lose (their data, their team's access)- Don't blame ("your payment failed" not "you failed to pay")- Include support contact for help- Plain text performs better than designed emails for dunning
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 2
High risk

High-value accounts may be blocked from cancelling unless they contact customer success

Source references: 2
What we found

The reference flow explicitly blocks self-service cancellation for accounts at $2,000+ MRR and routes $500–$2,000 accounts to customer success before cancellation completes. This directly conflicts with the same file’s statements that online signup cannot require phone cancellation and cancellation must be as easy as signup.

Why this matters

Customers may remain billable against their wishes or have to endure a retention conversation before stopping service. The business may face complaints, charge disputes, and consumer-protection exposure.

The reference routes higher-revenue accounts through customer success and explicitly blocks self-service cancellation above $2,000 MRR. For customers who subscribed online, this could delay cancellation and cause another charge; the file's own compliance notes say an online signup cannot require a phone call to cancel. Users can ask the author to remove revenue-based cancellation blocks and make customer-success contact optional and skippable.

references/cancel-flow-patterns.md:55In the instructionsOpen original file
| Account MRR | Cancel Flow ||-------------|-------------|| <$100/mo | Automated flow with offers || $100-$500/mo | Automated + flag for CS follow-up || $500-$2,000/mo | Route to CS before cancel completes || $2,000+/mo | Block self-serve cancel, require CS call |
Show 1 other places
references/cancel-flow-patterns.md:300In the instructionsOpen original file
### FTC Click-to-Cancel Rule (US)- Cancellation must be as easy as signup- Cannot require a phone call to cancel if signup was online- Cannot add excessive steps to discourage cancellation- Save offers are allowed but "continue cancelling" must be clear
Medium risk

Paused subscriptions auto-reactivate, potentially causing unexpected charges

Source references: 1
What we found

The pause playbook recommends selecting the shortest pause by default and automatically reactivating after an advance email. It does not require explicit acceptance of the reactivation date, resumed price, and future charge when the pause is chosen.

Why this matters

A customer who misses or overlooks the reminder may be charged while believing the subscription remains paused, leading to refunds, chargebacks, and loss of trust.

The pause design defaults to one month and automatically reactivates after a seven-day advance email. If the acceptance screen does not clearly disclose the restart date, price, and automatic charge, a customer who misses the email could be charged unexpectedly. The text does not prove implementation or describe the consent screen; users can require explicit confirmation of these terms and an easy way to disable reactivation before it occurs.

references/cancel-flow-patterns.md:137In the instructionsOpen original file
| Setting | Recommendation ||---------|---------------|| Pause duration options | 1 month, 2 months, 3 months || Default selection | 1 month (shortest) || Maximum pause | 3 months (longer pauses rarely return) || During pause | Keep data, remove access || Reactivation | Auto-reactivate with 7-day advance email || Repeat pauses | Allow 1 pause per 12-month period |

Inside this skill

8 instruction sections

This Skill is an advisory subscription-retention playbook with no executable scripts. It covers cancellation-flow optimization, churn prediction, and failed-payment recovery, and asks the agent to read local product-marketing material first.

View source
SKILL.md:15In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
SKILL.md:55In the instructionsOpen original file
This skill supports three modes:1. **Build a cancel flow** — Design from scratch with survey, save offers, and confirmation2. **Optimize an existing flow** — Analyze cancel data and improve save rates3. **Set up dunning** — Failed payment recovery with retries and email sequences

The main cancellation design asks for a reason survey followed by a targeted offer, while explicitly requiring the continue-cancellation option to remain visible and cancellation to be confirmed if the customer persists.

View source
SKILL.md:76In the instructionsOpen original file
**Step 2: Exit Survey**Ask why they're cancelling. This determines which save offer to show.**Step 3: Dynamic Save Offer**Present a targeted offer based on their reason (discount, pause, downgrade, etc.)**Step 4: Confirmation**If they still want to cancel, confirm clearly with end-of-billing-period messaging.**Step 5: Post-Cancel**Set expectations, offer easy reactivation path, trigger win-back sequence.
SKILL.md:197In the instructionsOpen original file
**UI principles:**- Keep the "continue cancelling" option visible (no dark patterns)- One primary offer + one fallback, not a wall of options- Show specific dollar savings, not abstract percentages

The payment-recovery guidance recommends retries based on decline type, dunning emails, and pausing or cancelling the account after a grace period.

View source
SKILL.md:284In the instructionsOpen original file
| Decline Type | Examples | Retry Strategy ||-------------|----------|----------------|| Soft decline (temporary) | Insufficient funds, processor timeout | Retry 3-5 times over 7-10 days || Hard decline (permanent) | Card stolen, account closed | Don't retry — ask for new card || Authentication required | 3D Secure, SCA | Send customer to update payment |
references/dunning-playbook.md:243In the instructionsOpen original file
|---------|---------------|| Duration | 7-14 days after final retry || Access | Degraded (read-only) or full access || Visibility | In-app banner: "Payment past due — update to continue" || Retry | Continue background retries during grace || Communication | Dunning emails continue |
Start here · InstructionsSKILL.md
churn-prevention
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 1 more sections are available in the original file.

File reference map

References: 2
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records4 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • references/cancel-flow-patterns.mdFull text included
  • references/dunning-playbook.mdFull text included
  • evals/evals.jsonFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • evals/evals.jsonSupporting file
  • references/cancel-flow-patterns.mdSupporting file
  • references/dunning-playbook.mdSupporting file
Lines read
1,245
File checksum (to compare versions)
ef0dcf336344be5a25492b1f468450ed08b59094de45ab2aa94db4f415b41ced