Skip to content
Report library
Purpose / Other

Cold Email Skill Security Audit

What the author says it does (original text)

Write B2B cold emails and follow-up sequences that get replies. Use when the user wants to write cold outreach emails, prospecting emails, cold email campaigns, sales development emails, or SDR emails. Also use when the user mentions "cold outreach," "prospecting email," "outbound email," "email to leads," "reach out to prospects," "sales email," "follow-up email sequence," "nobody's replying to m

Independent security check

Security risks found

Files checked
7
Risks found
4
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 2
Medium risk

Reads hidden product-marketing files without per-use confirmation

Source references: 3
What we found

Once invoked, the Skill tells the agent to read any matching file at several predetermined paths before asking questions. Such a file may contain positioning, customer stories, revenue data, or other internal business information not intended for this drafting task.

Why this matters

The contents enter the agent’s processing context and could be paraphrased into an external prospect email, accidentally exposing confidential claims, customer names, or unpublished metrics.

This is an active instruction to read a local file automatically: if any named path exists, the agent should read it before asking questions. Its contents would enter the agent’s processing context, which may exceed what a user expected to disclose for one email task if the file contains customer, performance, or internal-positioning details. The evidence does not show third-party upload or file modification. Users can restrict readable paths or require confirmation after the file is identified.

SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
Show 2 other places
SKILL.md:19In the instructionsOpen original file
1. **Who are you writing to?** — Role, company, why them specifically2. **What do you want?** — The outcome (meeting, reply, intro, demo)3. **What's the value?** — The specific problem you solve for people like them4. **What's your proof?** — A result, case study, or credibility signal5. **Any research signals?** — Funding, hiring, LinkedIn posts, company news, tech stack changes
SKILL.md:12In the instructionsOpen original file
## Before Writing**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
Medium risk

Encourages individual profiling using demographic and psychographic traits

Source references: 4
What we found

The personalization guide recommends age, background, technology use, funding stage, values, passions, and beliefs, calling psychographics the highest-impact dimension. It also points to social activity, comments, interviews, and other sources for individual signals.

Why this matters

At campaign scale, this can create profiling that prospects did not expect and place sensitive or inferred traits into messages. Recipients may feel monitored, and the data use may exceed the reasonable context in which it was made public.

The personalization guide explicitly lists age, background, values, passions, and beliefs as profiling dimensions and labels psychographics the highest-impact dimension. It also points to LinkedIn activity, comments, podcasts, and talks as personal-signal sources. Collecting or inferring such traits can create privacy, intrusive-targeting, or discriminatory-decision risks. The Skill only advises research and writing; it does not automatically scrape data. Users can restrict inputs to public, job-relevant signals directly tied to the business issue and exclude sensitive traits or unsupported inferences.

references/personalization.md:31In the instructionsOpen original file
| Signal            | Where to find it                   | How to use it                                                                || ----------------- | ---------------------------------- | ---------------------------------------------------------------------------- || Recent funding    | Crunchbase, LinkedIn, press        | "Congrats on Series B — scaling teams fast usually creates X challenge"      || Job postings      | LinkedIn Jobs, careers page        | "Noticed you're hiring 3 SDRs — sounds like you're scaling outbound"         || Tech stack        | BuiltWith, Wappalyzer, HG Insights | "I see you're using HubSpot — most teams at your stage hit a ceiling with X" || LinkedIn activity | Posts, comments, job changes       | "Really enjoyed your post about X"                                           || Company news      | Google News, press releases        | "Congrats on acquiring X — integrating teams usually creates Y challenge"    || Podcast/talks     | Google, YouTube, podcasts          | "Caught your talk at SaaStr on X — really insightful"                        || Website changes   | Manual review                      | "Your new pricing page caught my eye — curious how it's converting"          |
Show 3 other places
references/personalization.md:53In the instructionsOpen original file
## The Four -Graphic Principles (Becc Holland)- **Demographic** — Age, profession, background- **Technographic** — Tech stack, tools used- **Firmographic** — Company size, funding, industry, growth stage- **Psychographic** — Values, passions, beliefs (highest-impact dimension)Tapping into what prospects are passionate about drives significantly higher response rates.
references/personalization.md:29In the instructionsOpen original file
## Research Signal Stack| Signal            | Where to find it                   | How to use it                                                                || ----------------- | ---------------------------------- | ---------------------------------------------------------------------------- || Recent funding    | Crunchbase, LinkedIn, press        | "Congrats on Series B — scaling teams fast usually creates X challenge"      || Job postings      | LinkedIn Jobs, careers page        | "Noticed you're hiring 3 SDRs — sounds like you're scaling outbound"         || Tech stack        | BuiltWith, Wappalyzer, HG Insights | "I see you're using HubSpot — most teams at your stage hit a ceiling with X" || LinkedIn activity | Posts, comments, job changes       | "Really enjoyed your post about X"                                           || Company news      | Google News, press releases        | "Congrats on acquiring X — integrating teams usually creates Y challenge"    || Podcast/talks     | Google, YouTube, podcasts          | "Caught your talk at SaaStr on X — really insightful"                        || Website changes   | Manual review                      | "Your new pricing page caught my eye — curious how it's converting"          |
references/personalization.md:70In the instructionsOpen original file
## What Feels Fake (avoid)- AI-generated emails with similar phrasing ("I hope this email finds you well")- Generic attention hacks disconnected from problem ("Cool that you went to UCLA!" → pitch)- Over-personalizing to creepiness- "I saw your LinkedIn profile and wanted to reach out" — signals mass automation
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 2
Medium risk

Recommends disguising cold outreach as colleague email to increase opens

Source references: 2
What we found

The Skill explicitly says subjects should look as though they came from a colleague, while its reference calls this “internal camouflage.” This uses recipients’ trust in internal-looking messages to avoid being recognized as sales outreach.

Why this matters

Recipients may open a message because they mistake it for internal or established correspondence. In a real campaign, this can damage the sender’s reputation and increase complaints or blocking.

This is active writing guidance, not an example or warning. The Skill asks for cold-email subjects that look as though they came from a colleague, and the reference explicitly calls this “Internal Camouflage” intended to avoid being categorized as sales before opening. That can mislead recipients about the message’s source or nature. It only drafts copy and does not send it; users can require subjects that clearly signal a commercial approach rather than internal communication.

SKILL.md:91In the instructionsOpen original file
Short, boring, internal-looking. The subject line's only job is to get the email opened — not to sell.- 2-4 words, lowercase, no punctuation tricks- Should look like it came from a colleague ("reply rates," "hiring ops," "Q2 forecast")- No product pitches, no urgency, no emojis, no prospect's first name
Show 1 other places
references/subject-lines.md:12In the instructionsOpen original file
## Internal Camouflage PrincipleSubject lines that look like they came from a colleague, not a vendor, double open rates (Gong). Buyers mentally categorize before opening — if it looks like sales, it's filtered.**High-performing examples:** "reply rates" · "trial delays" · "hiring ops" · "employee turnover" · "Q2 forecast" · "new patients" · "personalization issue" · "second page"
Medium risk

Repeated unsolicited sequences can create complaint, domain-reputation, and compliance risk

Source references: 5
What we found

The Skill targets prospects who have not opted in and recommends up to four follow-ups after no response. Its own reference says spam complaints triple by the fourth follow-up, but it does not require checks for consent, suppression lists, unsubscribe handling, or applicable rules before drafting.

Why this matters

If the copy is placed directly into an automated campaign, recipients may be harassed, spam complaints may rise, sender-domain or mailbox deliverability may suffer, and regulated regions may create compliance exposure.

The active guidance recommends up to four follow-ups after no reply, while its own reference says spam complaints triple by the fourth follow-up. Repeated contact can affect sender reputation and may conflict with recipient objections or applicable marketing rules; the only explicit stop rule concerns the final breakup email. The Skill drafts rather than sends messages, so the risk arises if a user deploys the sequence. Users can ask for consent, suppression-list, opt-out, and applicable-law checks.

evals/evals.json:83In the instructionsOpen original file
      "id": 6,      "prompt": "Can you help me set up an automated email drip campaign for leads who download our whitepaper?",      "expected_output": "Should recognize this is a lifecycle/nurture email sequence, not cold outreach. Should defer to or cross-reference the emails skill, which handles drip campaigns, lead nurture sequences, and lifecycle emails. Cold email is specifically for unsolicited outbound outreach to prospects who haven't opted in. Should make this distinction clear.",      "assertions": [        "Recognizes this as lifecycle/nurture email, not cold outreach",        "References or defers to emails skill",        "Explains the distinction between cold email and lifecycle email",        "Does not attempt to design a nurture sequence using cold email patterns"      ],
Show 4 other places
references/follow-up-sequences.md:7In the instructionsOpen original file
- Highest single-email reply rate: **8.4%** (Belkins).- 4–7 email campaigns achieve **27% reply rates** vs 9% for 1–3 emails (Woodpecker, 20M emails).- By 4th follow-up, response rates drop **55%** and spam complaints **triple**.- Resolution: longer sequences catch different timing windows. Cap at 4 follow-ups (5 total emails). Each must add genuinely new value.
references/follow-up-sequences.md:16In the instructionsOpen original file
| Touch         | Day   | Notes                                          || ------------- | ----- | ---------------------------------------------- || Initial email | 0     | Maximum personalization investment             || Follow-up 1   | 3     | Waiting 3 days increases response by up to 31% || Follow-up 2   | 7–8   | Different angle                                || Follow-up 3   | 14    | New value piece                                || Follow-up 4   | 21–28 | Breakup email                                  |
SKILL.md:101In the instructionsOpen original file
## Follow-Up SequencesEach follow-up should add something new — a different angle, fresh proof, a useful resource. "Just checking in" gives the reader no reason to respond.- 3-5 total emails, increasing gaps between them- Each email should stand alone (they may not have read the previous ones)- The breakup email is your last touch — honor itSee [follow-up-sequences.md](references/follow-up-sequences.md) for cadence, angle rotation, and breakup email templates.
references/follow-up-sequences.md:65In the instructionsOpen original file
**Critical rule:** If you send a breakup email, honor it. Do not contact the prospect again.

Inside this skill

8 instruction sections

The Skill primarily drafts B2B cold emails, including subject lines, body copy, personalization, and follow-up sequences. The supplied files contain no implementation for sending email, installing software, or executing scripts.

View source
SKILL.md:2In the instructionsOpen original file
---name: cold-emaildescription: Write B2B cold emails and follow-up sequences that get replies. Use when the user wants to write cold outreach emails, prospecting emails, cold email campaigns, sales development emails, or SDR emails. Also use when the user mentions "cold outreach," "prospecting email," "outbound email," "email to leads," "reach out to prospects," "sales email," "follow-up email sequence," "nobody's replying to my emails," or "how do I write a cold email." Covers subject lines, opening lines, body copy, CTAs, personalization, and multi-touch follow-up sequences. For warm/lifecycle email sequences, see emails. For sales collateral beyond emails, see sales-enablement.metadata:

Before drafting, it automatically looks for a product-marketing context file in the project and uses its contents in the email-writing task.

View source
SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.

The Skill recommends sequences of up to five emails and explicitly says not to contact a prospect again after the final breakup email.

View source
references/follow-up-sequences.md:7In the instructionsOpen original file
- Highest single-email reply rate: **8.4%** (Belkins).- 4–7 email campaigns achieve **27% reply rates** vs 9% for 1–3 emails (Woodpecker, 20M emails).- By 4th follow-up, response rates drop **55%** and spam complaints **triple**.- Resolution: longer sequences catch different timing windows. Cap at 4 follow-ups (5 total emails). Each must add genuinely new value.
references/follow-up-sequences.md:65In the instructionsOpen original file
**Critical rule:** If you send a breakup email, honor it. Do not contact the prospect again.
Start here · InstructionsSKILL.md
cold-email
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 2 more sections are available in the original file.

File reference map

References: 5
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records7 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • references/benchmarks.mdFull text included
  • references/follow-up-sequences.mdFull text included
  • references/frameworks.mdFull text included
  • references/personalization.mdFull text included
  • references/subject-lines.mdFull text included
  • evals/evals.jsonFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • evals/evals.jsonSupporting file
  • references/benchmarks.mdSupporting file
  • references/follow-up-sequences.mdSupporting file
  • references/frameworks.mdSupporting file
  • references/personalization.mdSupporting file
  • references/subject-lines.mdSupporting file

Operations mentioned in code and instructions

Connect to websites
SKILL.md:51In the instructionsOpen original file
Interest-based CTAs ("Worth exploring?" / "Would this be useful?") beat meeting requests. One CTA per email. Make it easy to say yes with a one-line reply.
Lines read
646
File checksum (to compare versions)
01a1b830ce8bc8bd711998829c3eecafea27f2236052257217e4efc26ea6ee73