跳转到正文
报告库
用途分类 / 其他用途

Churn Prevention Skill 安全审计

作者说它能做什么(原文)

When the user wants to reduce churn, build cancellation flows, set up save offers, recover failed payments, or implement retention strategies. Also use when the user mentions 'churn,' 'cancel flow,' 'offboarding,' 'save offer,' 'dunning,' 'failed payment recovery,' 'win-back,' 'retention,' 'exit survey,' 'pause subscription,' 'involuntary churn,' 'people keep canceling,' 'churn rate is too high,'

第三方安全检查结论

先别安装或运行

已检查文件
4
发现的风险
4
会不会运行危险命令?检查是否下载程序后直接运行、让他人远程控制电脑,或藏起要运行的命令。未发现风险
会不会泄露文件和密钥?检查是否发送含密码或密钥的文件,以及代码里是否直接写了密钥。发现 1 项风险
中风险

流失预测会集中监控客户行为和敏感离开信号

原文依据:4 处
发现了什么

该方案要求监控登录、功能使用、支持工单、邮件打开、账单页访问、席位移除、数据导出和 NPS,并按套餐、收入、任期、使用量及过去优惠进行细分。这会形成可用于商业干预的客户行为画像。

为什么需要注意

如果没有告知、合法依据、访问限制和保留期限,员工或系统可能不当使用详细行为记录;数据泄露时也会暴露客户的业务状况、离开意图和账户价值。

该方案建议持续汇总登录、功能使用、支持互动、邮件打开、账单页访问、席位移除、数据导出和 NPS,并进一步按收入、任期、使用量和历史优惠细分,以触发商业干预。这会形成详细的客户行为画像;若缺少告知、合法依据、最小化和保留期限,可能影响隐私并导致差别化对待。用户可要求只收集必要信号、限制用途与保存期,并允许客户了解或退出非必要画像。

SKILL.md:218来自说明文档打开原文件
|--------|-----------|-----------|| Login frequency drops 50%+ | High | 2-4 weeks before cancel || Key feature usage stops | High | 1-3 weeks before cancel || Support tickets spike then stop | High | 1-2 weeks before cancel || Email open rates decline | Medium | 2-6 weeks before cancel || Billing page visits increase | High | Days before cancel || Team seats removed | High | 1-2 weeks before cancel || Data export initiated | Critical | Days before cancel || NPS score drops below 6 | Medium | 1-3 months before cancel |
查看另外 3 个位置
references/cancel-flow-patterns.md:239来自说明文档打开原文件
| Dimension | Why It Matters ||-----------|---------------|| Plan / MRR | Higher-value customers get personal outreach || Tenure | Long-term customers get more generous offers || Usage level | High-usage customers get different messaging than dormant ones || Billing interval | Monthly vs. annual need different approaches || Previous saves | Don't re-offer the same discount to a repeat canceller || Cancel reason | Drives which offer to show (core mapping) |
SKILL.md:214来自说明文档打开原文件
Track these leading indicators of churn:| Signal | Risk Level | Timeframe ||--------|-----------|-----------|| Login frequency drops 50%+ | High | 2-4 weeks before cancel || Key feature usage stops | High | 1-3 weeks before cancel || Support tickets spike then stop | High | 1-2 weeks before cancel || Email open rates decline | Medium | 2-6 weeks before cancel || Billing page visits increase | High | Days before cancel || Team seats removed | High | 1-2 weeks before cancel || Data export initiated | Critical | Days before cancel || NPS score drops below 6 | Medium | 1-3 months before cancel |
references/cancel-flow-patterns.md:306来自说明文档打开原文件
### GDPR / Data Retention (EU)- Inform users about data retention period post-cancel- Offer data export before account deletion- Honor deletion requests within 30 days- Don't use post-cancel data for marketing without consent
会不会删除文件或一直在后台运行?检查是否大范围删除文件、改写磁盘,或设置自动启动。未发现风险
会不会绕过安全保护?检查是否跳过网站安全验证、开放过多文件权限,或取消操作前的确认。发现 1 项风险
中风险

建议免登录打开付款更新页,但未要求保护链接

原文依据:1 处
发现了什么

Skill 建议付款更新链接尽可能无需登录,却没有同时规定链接必须一次性、短期有效、限定客户与操作范围。免登录本身可以安全实现,但缺少这些约束会使被转发、泄露或猜中的链接成为账户或付款资料操作入口。

为什么需要注意

持有链接的非授权人员可能查看账户相关信息、修改付款方式,或把自己的付款方式绑定到错误账户。

Skill 主动建议付款更新链接尽可能免登录。若实现为长期有效、可转发或范围过宽的链接,拿到链接的人可能访问或修改他人的付款设置。源码未说明链接是否受一次性令牌、短有效期、客户绑定或重新验证保护,因此风险是否实际存在取决于实现。用户可要求作者明确这些保护,并限制链接只能完成指定客户的一次付款更新。

SKILL.md:308来自说明文档打开原文件
**Dunning email best practices:**- Direct link to payment update page (no login required if possible)- Show what they'll lose (their data, their team's access)- Don't blame ("your payment failed" not "you failed to pay")- Include support contact for help- Plain text performs better than designed emails for dunning
会不会误导 AI 或隐藏内容?检查工作说明是否要求 AI 忽略你的指令、干扰检查结果,或夹带看不见的文字。未发现风险
会不会偷偷改推广链接或收款方?检查是否强制替换推广链接或收款对象,同时要求隐瞒更改。发现 2 项风险
高风险

高价账户的取消可能被阻止并被迫联系客户成功团队

原文依据:2 处
发现了什么

参考流程明确要求月费达到 2,000 美元的账户不能自助取消,500–2,000 美元的账户也要在完成取消前转给客户成功团队。这与同一文件所述“线上注册不得要求电话取消”和“取消必须与注册同样容易”直接冲突。

为什么需要注意

实施后,客户可能在不愿继续的情况下仍被续费,或必须经历销售挽留才能停止订阅;企业还可能面临投诉、退款争议和消费者保护风险。

该参考流程把高收入账户的取消交给客户成功团队,并明确要求月费 2,000 美元以上的账户不能自助取消。如果客户在线订阅,这可能拖延或阻止取消并造成额外续费;文件自己的合规说明也称在线注册不能被要求电话取消。用户可要求作者移除收入门槛造成的取消阻断,并确保客户成功沟通始终可跳过。

references/cancel-flow-patterns.md:55来自说明文档打开原文件
| Account MRR | Cancel Flow ||-------------|-------------|| <$100/mo | Automated flow with offers || $100-$500/mo | Automated + flag for CS follow-up || $500-$2,000/mo | Route to CS before cancel completes || $2,000+/mo | Block self-serve cancel, require CS call |
查看另外 1 个位置
references/cancel-flow-patterns.md:300来自说明文档打开原文件
### FTC Click-to-Cancel Rule (US)- Cancellation must be as easy as signup- Cannot require a phone call to cancel if signup was online- Cannot add excessive steps to discourage cancellation- Save offers are allowed but "continue cancelling" must be clear
中风险

暂停订阅会被默认自动恢复,可能产生用户未预期的收费

原文依据:1 处
发现了什么

暂停方案建议默认选择最短暂停期,并在期满后自动恢复订阅,仅以提前邮件通知。它没有要求用户在接受暂停时明确同意恢复日期、恢复价格和自动扣款。

为什么需要注意

忽略或未收到提醒邮件的用户可能在认为订阅仍暂停时被重新收费,造成退款、拒付和信任损失。

暂停方案默认选择一个月,并规定到期后自动恢复,只提前七天发邮件。如果接受暂停时没有清楚展示恢复日期、价格和自动扣款,未注意邮件的客户可能遭遇意外收费。文本没有证明已实施,也未说明同意界面;用户可要求在接受暂停时明确确认这些条款,并提供到期前取消自动恢复的入口。

references/cancel-flow-patterns.md:137来自说明文档打开原文件
| Setting | Recommendation ||---------|---------------|| Pause duration options | 1 month, 2 months, 3 months || Default selection | 1 month (shortest) || Maximum pause | 3 months (longer pauses rarely return) || During pause | Keep data, remove access || Reactivation | Auto-reactivate with 7-day advance email || Repeat pauses | Allow 1 pause per 12-month period |

Skill 逻辑拆解

8 个说明模块

该 Skill 是一套订阅留存建议,没有提供可执行脚本。它覆盖取消流程优化、流失预测和失败付款追回,并建议先读取本地产品营销资料作为上下文。

查看原文
SKILL.md:15来自说明文档打开原文件
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
SKILL.md:55来自说明文档打开原文件
This skill supports three modes:1. **Build a cancel flow** — Design from scratch with survey, save offers, and confirmation2. **Optimize an existing flow** — Analyze cancel data and improve save rates3. **Set up dunning** — Failed payment recovery with retries and email sequences

取消流程的主体设计要求先调查取消原因,再显示针对性优惠;同时明确要求继续取消选项可见,并在用户坚持时确认取消。

查看原文
SKILL.md:76来自说明文档打开原文件
**Step 2: Exit Survey**Ask why they're cancelling. This determines which save offer to show.**Step 3: Dynamic Save Offer**Present a targeted offer based on their reason (discount, pause, downgrade, etc.)**Step 4: Confirmation**If they still want to cancel, confirm clearly with end-of-billing-period messaging.**Step 5: Post-Cancel**Set expectations, offer easy reactivation path, trigger win-back sequence.
SKILL.md:197来自说明文档打开原文件
**UI principles:**- Keep the "continue cancelling" option visible (no dark patterns)- One primary offer + one fallback, not a wall of options- Show specific dollar savings, not abstract percentages

付款追回部分建议根据拒付类型安排重试、发送催款邮件,并在宽限期后暂停或取消账户。

查看原文
SKILL.md:284来自说明文档打开原文件
| Decline Type | Examples | Retry Strategy ||-------------|----------|----------------|| Soft decline (temporary) | Insufficient funds, processor timeout | Retry 3-5 times over 7-10 days || Hard decline (permanent) | Card stolen, account closed | Don't retry — ask for new card || Authentication required | 3D Secure, SCA | Send customer to update payment |
references/dunning-playbook.md:243来自说明文档打开原文件
|---------|---------------|| Duration | 7-14 days after final retry || Access | Degraded (read-only) or full access || Visibility | In-app banner: "Payment past due — update to continue" || Retry | Continue background retries during grace || Communication | Dunning emails continue |
从这里开始 · 工作说明SKILL.md
churn-prevention
连线表示工作说明包含的模块,不是实际运行顺序。点击模块可查看原文。 另有 1 个章节,可在原文件中查看。

文件引用关系图

2 处引用
哪些文件发起引用引用了什么
连线表示真实的文件引用,不是运行顺序。点击节点可高亮相关连线,并查看具体文件和原文位置。虚线表示还有文件需要定位。
文件与检查记录4 个文件

检查范围与遗漏

逐文件查看涉及的内容

下方列出本次涉及的原文范围;纳入检查不代表已查清所有问题。

  • SKILL.md已纳入全文
  • references/cancel-flow-patterns.md已纳入全文
  • references/dunning-playbook.md已纳入全文
  • evals/evals.json已纳入全文

这份报告只针对上方版本。我们看了拿到的代码和说明文件,没有实际运行 Skill,也没有检查它另外安装的软件包。因此,这不是“保证安全”的承诺;换了版本或使用环境,结果也可能不同。

  • SKILL.md工作说明
  • evals/evals.json配套文件
  • references/cancel-flow-patterns.md配套文件
  • references/dunning-playbook.md配套文件
读取了多少行
1,245
文件校验值(用于核对版本)
ef0dcf336344be5a25492b1f468450ed08b59094de45ab2aa94db4f415b41ced