Skip to content
Report library
Purpose / Other

Emails Skill Security Audit

What the author says it does (original text)

When the user wants to create or optimize an email sequence, drip campaign, automated email flow, or lifecycle email program. Also use when the user mentions "email sequence," "drip campaign," "nurture sequence," "onboarding emails," "welcome sequence," "re-engagement emails," "email automation," "lifecycle emails," "trigger-based emails," "email funnel," "email workflow," "what emails should I se

Independent security check

No obvious risks found in this check

Files checked
5
Risks found
0
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.No risks found
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

8 instruction sections

The Skill primarily designs multi-email marketing flows: it first gathers audience, trigger, and conversion context, then outputs timing, subject lines, body copy, CTAs, segment conditions, and a metrics plan.

View source
SKILL.md:17In the instructionsOpen original file
Before creating a sequence, understand:1. **Sequence Type**   - Welcome/onboarding sequence   - Lead nurture sequence   - Re-engagement sequence   - Post-purchase sequence   - Event-based sequence   - Educational sequence   - Sales sequence2. **Audience Context**   - Who are they?   - What triggered them into this sequence?   - What do they already know/believe?   - What's their current relationship with you?3. **Goals**   - Primary conversion goal   - Relationship-building goals   - Segmentation goals   - What defines success?
SKILL.md:262In the instructionsOpen original file
### For Each Email```Email [#]: [Name/Purpose]Send: [Timing]Subject: [Subject line]Preview: [Preview text]Body: [Full copy]CTA: [Button text] → [Link destination]Segment/Conditions: [If applicable]```### Metrics PlanWhat to measure and benchmarks

At runtime, the Skill first checks for and reads a product-marketing context file in the project. This is relevant to tailoring emails, but the file may contain internal business information not repeated in the current request; users should confirm that the named files are appropriate for AI processing. The visible content does not direct the Skill to upload that file’s contents to an email service.

View source
SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.

The references recommend personalization and segmentation using opens, clicks, activity, account stage, industry, role, and actual product usage. This may involve customer behavioral and account data, but the visible files provide design guidance only; they contain no implementation that reads a customer database, sends mail, or changes accounts.

View source
references/copy-guidelines.md:54In the instructionsOpen original file
## Personalization### Merge Fields- First name (fallback to "there" or "friend")- Company name (B2B)- Relevant data (usage, plan, etc.)### Dynamic Content- Based on segment- Based on behavior- Based on stage### Triggered Emails- Action-based sends- More relevant than time-based- Examples: Feature used, milestone hit, inactivity
references/copy-guidelines.md:73In the instructionsOpen original file
## Segmentation Strategies### By Behavior- Openers vs. non-openers- Clickers vs. non-clickers- Active vs. inactive### By Stage- Trial vs. paid- New vs. long-term- Engaged vs. at-risk### By Profile- Industry/role (B2B)- Use case / goal- Company size
references/email-types.md:311In the instructionsOpen original file
**Structure**:- Key metrics at a glance- Notable achievements- Activity breakdown- Suggestions / what to try next- CTA to dive deeper**Personalization**: Must be relevant to their actual usage. Empty reports are worse than no report.

The Skill lists several third-party email platforms as implementation references, but the visible instructions do not require automatically connecting to them, requesting credentials, or sending marketing mail. If implementation later introduces the unprovided tool registry or integration guides, their permissions and data flows should be reviewed separately.

View source
SKILL.md:288In the instructionsOpen original file
## Tool IntegrationsFor implementation, see the [tools registry](../../tools/REGISTRY.md). Key email tools:| Tool | Best For | MCP | Guide ||------|----------|:---:|-------|| **Customer.io** | Behavior-based automation | - | [customer-io.md](../../tools/integrations/customer-io.md) || **Mailchimp** | SMB email marketing | ✓ | [mailchimp.md](../../tools/integrations/mailchimp.md) || **Nitrosend** | AI-native email (sequences via prompts) | ✓ | [nitrosend.md](../../tools/integrations/nitrosend.md) || **Resend** | Developer-friendly transactional | ✓ | [resend.md](../../tools/integrations/resend.md) || **SendGrid** | Transactional email at scale | - | [sendgrid.md](../../tools/integrations/sendgrid.md) || **Kit** | Creator/newsletter focused | - | [kit.md](../../tools/integrations/kit.md) |
Start here · InstructionsSKILL.md
emails
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 2 more sections are available in the original file.

File reference map

References: 3
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records5 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • references/copy-guidelines.mdFull text included
  • references/email-types.mdFull text included
  • references/sequence-templates.mdFull text included
  • evals/evals.jsonFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • evals/evals.jsonSupporting file
  • references/copy-guidelines.mdSupporting file
  • references/email-types.mdSupporting file
  • references/sequence-templates.mdSupporting file
Lines read
1,205
File checksum (to compare versions)
db382d1ec50e48848e1927663c8bbc8bfc35c66f1db16d1d8e5052a06b32a7cc