跳转到正文
报告库
用途分类 / 其他用途

Cold Email Skill 安全审计

作者说它能做什么(原文)

Write B2B cold emails and follow-up sequences that get replies. Use when the user wants to write cold outreach emails, prospecting emails, cold email campaigns, sales development emails, or SDR emails. Also use when the user mentions "cold outreach," "prospecting email," "outbound email," "email to leads," "reach out to prospects," "sales email," "follow-up email sequence," "nobody's replying to m

第三方安全检查结论

发现安全风险

已检查文件
7
发现的风险
4
会不会运行危险命令?检查是否下载程序后直接运行、让他人远程控制电脑,或藏起要运行的命令。未发现风险
会不会泄露文件和密钥?检查是否发送含密码或密钥的文件,以及代码里是否直接写了密钥。发现 2 项风险
中风险

未经逐次确认读取隐藏的产品营销文件

原文依据:3 处
发现了什么

调用该 Skill 后,只要几个预定路径之一存在,代理就被要求在提问前读取它。文件可能包含未准备交给此写作任务的定位、客户案例、收入数据或其他内部商业信息。

为什么需要注意

这些内容会进入代理处理上下文,并可能被改写进面向外部潜在客户的邮件;敏感的内部说法、客户名称或未公开指标因此可能意外泄露。

这是自动读取本地文件的实际指令:只要任一约定路径存在,代理就应在提问前读取。读取内容会进入代理处理上下文;如果文件含客户、业绩或内部定位信息,可能超出用户对单次邮件任务的预期披露范围。证据没有显示文件会上传给第三方或写回磁盘。用户可在使用前限制允许读取的路径,或要求先列出并征得确认。

SKILL.md:14来自说明文档打开原文件
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
查看另外 2 个位置
SKILL.md:19来自说明文档打开原文件
1. **Who are you writing to?** — Role, company, why them specifically2. **What do you want?** — The outcome (meeting, reply, intro, demo)3. **What's the value?** — The specific problem you solve for people like them4. **What's your proof?** — A result, case study, or credibility signal5. **Any research signals?** — Funding, hiring, LinkedIn posts, company news, tech stack changes
SKILL.md:12来自说明文档打开原文件
## Before Writing**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
中风险

鼓励用人口与心理特征对潜在客户进行个体画像

原文依据:4 处
发现了什么

个性化指南建议收集年龄、背景、技术栈、资金阶段、价值观、热情和信念,并把心理特征称为影响最高的维度。它还建议从社交活动、评论、访谈和其他来源获取个人信号。

为什么需要注意

在规模化营销中,这可能形成未经预期的个人画像,并把敏感或推断出的特征写入邮件。收件人可能感到被监视,数据使用也可能超出原始公开场景的合理预期。

个性化指南确实把年龄、背景、价值观、热情和信念列为画像维度,并将心理特征称为影响最高的维度;它也列出 LinkedIn 活动、评论、播客和访谈等个人信号来源。若用户据此收集或推断敏感个人特征,可能侵犯隐私、造成令人不适的定向联系或产生歧视性决策。它仅提供研究与写作建议,未自动抓取数据。用户可限制为公开、职业相关且与业务问题直接相关的信号,并排除敏感属性和未经证实的推断。

references/personalization.md:31来自说明文档打开原文件
| Signal            | Where to find it                   | How to use it                                                                || ----------------- | ---------------------------------- | ---------------------------------------------------------------------------- || Recent funding    | Crunchbase, LinkedIn, press        | "Congrats on Series B — scaling teams fast usually creates X challenge"      || Job postings      | LinkedIn Jobs, careers page        | "Noticed you're hiring 3 SDRs — sounds like you're scaling outbound"         || Tech stack        | BuiltWith, Wappalyzer, HG Insights | "I see you're using HubSpot — most teams at your stage hit a ceiling with X" || LinkedIn activity | Posts, comments, job changes       | "Really enjoyed your post about X"                                           || Company news      | Google News, press releases        | "Congrats on acquiring X — integrating teams usually creates Y challenge"    || Podcast/talks     | Google, YouTube, podcasts          | "Caught your talk at SaaStr on X — really insightful"                        || Website changes   | Manual review                      | "Your new pricing page caught my eye — curious how it's converting"          |
查看另外 3 个位置
references/personalization.md:53来自说明文档打开原文件
## The Four -Graphic Principles (Becc Holland)- **Demographic** — Age, profession, background- **Technographic** — Tech stack, tools used- **Firmographic** — Company size, funding, industry, growth stage- **Psychographic** — Values, passions, beliefs (highest-impact dimension)Tapping into what prospects are passionate about drives significantly higher response rates.
references/personalization.md:29来自说明文档打开原文件
## Research Signal Stack| Signal            | Where to find it                   | How to use it                                                                || ----------------- | ---------------------------------- | ---------------------------------------------------------------------------- || Recent funding    | Crunchbase, LinkedIn, press        | "Congrats on Series B — scaling teams fast usually creates X challenge"      || Job postings      | LinkedIn Jobs, careers page        | "Noticed you're hiring 3 SDRs — sounds like you're scaling outbound"         || Tech stack        | BuiltWith, Wappalyzer, HG Insights | "I see you're using HubSpot — most teams at your stage hit a ceiling with X" || LinkedIn activity | Posts, comments, job changes       | "Really enjoyed your post about X"                                           || Company news      | Google News, press releases        | "Congrats on acquiring X — integrating teams usually creates Y challenge"    || Podcast/talks     | Google, YouTube, podcasts          | "Caught your talk at SaaStr on X — really insightful"                        || Website changes   | Manual review                      | "Your new pricing page caught my eye — curious how it's converting"          |
references/personalization.md:70来自说明文档打开原文件
## What Feels Fake (avoid)- AI-generated emails with similar phrasing ("I hope this email finds you well")- Generic attention hacks disconnected from problem ("Cool that you went to UCLA!" → pitch)- Over-personalizing to creepiness- "I saw your LinkedIn profile and wanted to reach out" — signals mass automation
会不会删除文件或一直在后台运行?检查是否大范围删除文件、改写磁盘,或设置自动启动。未发现风险
会不会绕过安全保护?检查是否跳过网站安全验证、开放过多文件权限,或取消操作前的确认。未发现风险
会不会误导 AI 或隐藏内容?检查工作说明是否要求 AI 忽略你的指令、干扰检查结果,或夹带看不见的文字。未发现风险
会不会偷偷改推广链接或收款方?检查是否强制替换推广链接或收款对象,同时要求隐瞒更改。发现 2 项风险
中风险

建议把陌生开发邮件伪装成同事邮件以提高打开率

原文依据:2 处
发现了什么

该 Skill 明确要求主题“看起来像同事发来的”,参考资料还称其为“内部伪装”。这不只是简洁写作,而是利用收件人对内部邮件的信任来绕过其销售邮件判断。

为什么需要注意

收件人可能在误以为邮件与内部工作有关时打开它。若用于真实推广,可能损害发件人品牌信誉并增加投诉或屏蔽。

这是实际写作指令,不是示例或警告。Skill 要求陌生邮件主题看起来像同事邮件,参考资料还明确以“Internal Camouflage”描述其目的:让收件人在打开前不把邮件判断为销售邮件。这可能误导收件人对邮件来源或性质的判断。它只生成文案,并不自行发送;用户可要求主题明确反映商业联系,不冒充内部沟通。

SKILL.md:91来自说明文档打开原文件
Short, boring, internal-looking. The subject line's only job is to get the email opened — not to sell.- 2-4 words, lowercase, no punctuation tricks- Should look like it came from a colleague ("reply rates," "hiring ops," "Q2 forecast")- No product pitches, no urgency, no emojis, no prospect's first name
查看另外 1 个位置
references/subject-lines.md:12来自说明文档打开原文件
## Internal Camouflage PrincipleSubject lines that look like they came from a colleague, not a vendor, double open rates (Gong). Buyers mentally categorize before opening — if it looks like sales, it's filtered.**High-performing examples:** "reply rates" · "trial delays" · "hiring ops" · "employee turnover" · "Q2 forecast" · "new patients" · "personalization issue" · "second page"
中风险

多轮陌生邮件可能增加投诉、域名信誉和合规风险

原文依据:5 处
发现了什么

该 Skill 面向未主动订阅的潜在客户,并建议在对方没有回复时继续发送最多四次跟进。资料自身承认到第四次跟进时垃圾邮件投诉会增加三倍,但没有要求在起草前检查同意、拒收名单、退订机制或适用规则。

为什么需要注意

若用户直接把文案投入自动化活动,可能骚扰收件人、提高垃圾邮件投诉率、损害发件域名或邮箱账户的送达能力,并在受监管地区产生合规风险。

该 Skill 实际建议在未回复后安排最多四次跟进;其资料同时承认到第四次跟进时垃圾邮件投诉会增至三倍。反复联系可能影响发件信誉,也可能与收件人的拒绝或当地营销规则冲突,而现有指令只要求在“分手邮件”后停止。Skill 本身只撰写邮件、不会发送,因此风险在用户采用并发送该序列时发生。用户可要求作者加入退订、拒收名单、同意和适用法律检查。

evals/evals.json:83来自说明文档打开原文件
      "id": 6,      "prompt": "Can you help me set up an automated email drip campaign for leads who download our whitepaper?",      "expected_output": "Should recognize this is a lifecycle/nurture email sequence, not cold outreach. Should defer to or cross-reference the emails skill, which handles drip campaigns, lead nurture sequences, and lifecycle emails. Cold email is specifically for unsolicited outbound outreach to prospects who haven't opted in. Should make this distinction clear.",      "assertions": [        "Recognizes this as lifecycle/nurture email, not cold outreach",        "References or defers to emails skill",        "Explains the distinction between cold email and lifecycle email",        "Does not attempt to design a nurture sequence using cold email patterns"      ],
查看另外 4 个位置
references/follow-up-sequences.md:7来自说明文档打开原文件
- Highest single-email reply rate: **8.4%** (Belkins).- 4–7 email campaigns achieve **27% reply rates** vs 9% for 1–3 emails (Woodpecker, 20M emails).- By 4th follow-up, response rates drop **55%** and spam complaints **triple**.- Resolution: longer sequences catch different timing windows. Cap at 4 follow-ups (5 total emails). Each must add genuinely new value.
references/follow-up-sequences.md:16来自说明文档打开原文件
| Touch         | Day   | Notes                                          || ------------- | ----- | ---------------------------------------------- || Initial email | 0     | Maximum personalization investment             || Follow-up 1   | 3     | Waiting 3 days increases response by up to 31% || Follow-up 2   | 7–8   | Different angle                                || Follow-up 3   | 14    | New value piece                                || Follow-up 4   | 21–28 | Breakup email                                  |
SKILL.md:101来自说明文档打开原文件
## Follow-Up SequencesEach follow-up should add something new — a different angle, fresh proof, a useful resource. "Just checking in" gives the reader no reason to respond.- 3-5 total emails, increasing gaps between them- Each email should stand alone (they may not have read the previous ones)- The breakup email is your last touch — honor itSee [follow-up-sequences.md](references/follow-up-sequences.md) for cadence, angle rotation, and breakup email templates.
references/follow-up-sequences.md:65来自说明文档打开原文件
**Critical rule:** If you send a breakup email, honor it. Do not contact the prospect again.

Skill 逻辑拆解

8 个说明模块

该 Skill 的主要功能是起草 B2B 冷邮件,包括主题、正文、个性化内容和多轮跟进;它本身没有提供发送邮件、安装软件或执行脚本的实现。

查看原文
SKILL.md:2来自说明文档打开原文件
---name: cold-emaildescription: Write B2B cold emails and follow-up sequences that get replies. Use when the user wants to write cold outreach emails, prospecting emails, cold email campaigns, sales development emails, or SDR emails. Also use when the user mentions "cold outreach," "prospecting email," "outbound email," "email to leads," "reach out to prospects," "sales email," "follow-up email sequence," "nobody's replying to my emails," or "how do I write a cold email." Covers subject lines, opening lines, body copy, CTAs, personalization, and multi-touch follow-up sequences. For warm/lifecycle email sequences, see emails. For sales collateral beyond emails, see sales-enablement.metadata:

在写作前,它会自动寻找并读取项目中的产品营销上下文文件,然后将其中的信息用于邮件。

查看原文
SKILL.md:14来自说明文档打开原文件
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.

该 Skill 建议最多发送五封邮件,并明确要求最终告别邮件之后不再联系对方。

查看原文
references/follow-up-sequences.md:7来自说明文档打开原文件
- Highest single-email reply rate: **8.4%** (Belkins).- 4–7 email campaigns achieve **27% reply rates** vs 9% for 1–3 emails (Woodpecker, 20M emails).- By 4th follow-up, response rates drop **55%** and spam complaints **triple**.- Resolution: longer sequences catch different timing windows. Cap at 4 follow-ups (5 total emails). Each must add genuinely new value.
references/follow-up-sequences.md:65来自说明文档打开原文件
**Critical rule:** If you send a breakup email, honor it. Do not contact the prospect again.
从这里开始 · 工作说明SKILL.md
cold-email
连线表示工作说明包含的模块,不是实际运行顺序。点击模块可查看原文。 另有 2 个章节,可在原文件中查看。

文件引用关系图

5 处引用
哪些文件发起引用引用了什么
连线表示真实的文件引用,不是运行顺序。点击节点可高亮相关连线,并查看具体文件和原文位置。虚线表示还有文件需要定位。
文件与检查记录7 个文件

检查范围与遗漏

逐文件查看涉及的内容

下方列出本次涉及的原文范围;纳入检查不代表已查清所有问题。

  • SKILL.md已纳入全文
  • references/benchmarks.md已纳入全文
  • references/follow-up-sequences.md已纳入全文
  • references/frameworks.md已纳入全文
  • references/personalization.md已纳入全文
  • references/subject-lines.md已纳入全文
  • evals/evals.json已纳入全文

这份报告只针对上方版本。我们看了拿到的代码和说明文件,没有实际运行 Skill,也没有检查它另外安装的软件包。因此,这不是“保证安全”的承诺;换了版本或使用环境,结果也可能不同。

  • SKILL.md工作说明
  • evals/evals.json配套文件
  • references/benchmarks.md配套文件
  • references/follow-up-sequences.md配套文件
  • references/frameworks.md配套文件
  • references/personalization.md配套文件
  • references/subject-lines.md配套文件

代码和说明中提到的操作

连接外部网站
SKILL.md:51来自说明文档打开原文件
Interest-based CTAs ("Worth exploring?" / "Would this be useful?") beat meeting requests. One CTA per email. Make it easy to say yes with a one-line reply.
读取了多少行
646
文件校验值(用于核对版本)
01a1b830ce8bc8bd711998829c3eecafea27f2236052257217e4efc26ea6ee73