Skills reactivation-specialist
πŸ“¦

reactivation-specialist

v19.0.0 Content revision r2 Safe βš™οΈ External commands🌐 Network accessπŸ“ Filesystem accessπŸ”‘ Env variables

Build a compliant email reactivation program

Lapsed subscriber lists can reduce deliverability and create consent risk. This skill designs a staged win-back program with fresh consent signals and clear suppression outcomes.

Supports: Claude Codex Code(CC)
πŸ₯ˆ 81 Silver

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "reactivation-specialist" from https://skillstore.io/skills/aaron-he-zhu-reactivation-specialist.md and its manifest at https://skillstore.io/api/skills/aaron-he-zhu-reactivation-specialist/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "reactivation-specialist". Create a plan for subscribers with no opens in 90 days.

Expected outcome:

  • Cohort: subscribers with no opens in 90 days, excluding suppressed and hard-bounced contacts.
  • Ladder: reminder, optional incentive, then a final confirmation message.
  • Terminal rule: click-to-confirm returns a subscriber to nurture; no response leads to suppression after the stated window.

Using "reactivation-specialist". We have no engagement export yet.

Expected outcome:

  • Status: Estimated because no export is available.
  • Plan: use the stated inactivity window and make the incentive step conditional.
  • Open loop: obtain recency, complaint, and unsubscribe data before launch.

Security Audit

Safe
v6 β€’ 7/27/2026 Open versioned report

Most static findings are false positives from Markdown backticks and relative documentation links. One confirmed issue remains: the save instruction uses a user-derived cohort-or-goal placeholder without requiring filename sanitization or path containment. The skill otherwise instructs the agent to treat imported data as untrusted and requires user confirmation before saving.

1
Files scanned
94
Lines analyzed
1
Review items
0
False positives ignored
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
Path traversal sequence
On user confirmation, save to `memory/email/reactivation-specialist/YYYY-MM-DD-<cohort-or-goal>.md`
The save path includes a cohort-or-goal placeholder that may be derived from user input. The instruction does not require filename validation or containment checks, so a host that follows it literally could write outside the intended directory.
Audited by: claude View Audit History β†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/aaron-he-zhu-reactivation-specialist/audits/6?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/aaron-he-zhu-reactivation-specialist/security.svg)](https://skillstore.io/skills/aaron-he-zhu-reactivation-specialist?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/aaron-he-zhu-reactivation-specialist?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/aaron-he-zhu-reactivation-specialist/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/aaron-he-zhu-reactivation-specialist.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA Β· BibTeX Β· CFF)

APA citation

aaron-he-zhu. (2026). reactivation-specialist security audit report (audit version 6) [Author version 19.0.0]. Skillstore. https://skillstore.io/skills/aaron-he-zhu-reactivation-specialist/audits/6

BibTeX citation

@techreport{aaron-he-zhu-aaron-he-zhu-reactivation-specialist-2026, author = {aaron-he-zhu}, title = {reactivation-specialist security audit report (audit version 6)}, institution = {Skillstore}, year = {2026}, number = {6}, url = {https://skillstore.io/skills/aaron-he-zhu-reactivation-specialist/audits/6}, note = {Author version 19.0.0} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "reactivation-specialist security audit report (audit version 6)" version: "19.0.0" type: report authors: - name: "aaron-he-zhu" date-released: "2026-07-27" url: "https://skillstore.io/skills/aaron-he-zhu-reactivation-specialist/audits/6" identifiers: - type: other value: "skillstore:aaron-he-zhu-reactivation-specialist:audit:6" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
100
Maintainability
87
Content
67
Community
91
Spec Compliance

What You Can Build

Recover inactive subscribers

Create a measured win-back sequence for subscribers who have not engaged within a defined period.

Run a re-permission sweep

Define a fresh opt-in action and a clear path for subscribers who do not respond.

Clean a declining mailing list

Set a safe sunset rule that protects deliverability without using a bulk deletion approach.

Try These Prompts

Define a basic win-back campaign
Build a win-back campaign for subscribers who have not opened an email in 90 days. I use [ESP] and can offer [incentive].
Create a re-permission plan
Design a re-permission sweep for our inactive subscribers. Use a three-step ladder, include a click-to-confirm action, and propose a suppression rule.
Use engagement data
Using this engagement export, define a lapsed cohort and reactivation plan. Label conclusions as Measured, User-provided, or Estimated. Our policy is [policy].
Prepare a governed handoff
Create a reactivation program for the retention profile. Include re-consent, frequency guardrails, terminal states, open questions, and a handoff summary for consent tracking.

Best Practices

  • Use a defined engagement window and exclude already suppressed contacts.
  • Require an explicit re-consent action before returning a subscriber to active nurture.
  • Limit reactivation touches and document the final suppression decision.

Avoid

  • Do not repeatedly message subscribers after the last-chance step.
  • Do not treat an email open alone as a fresh consent signal.
  • Do not design a suppression rule when lawful basis is unknown.

Frequently Asked Questions

What does this skill create?
It creates a lapsed-cohort definition, offer ladder, re-consent step, and sunset rule.
Does it send emails?
No. It creates a program specification and does not operate an email platform.
What data should I provide?
Provide the inactivity window, available incentive, suppression policy, and engagement export when available.
Can it work without an engagement export?
Yes. It can create an estimated plan from your stated window and identify the missing data.
How does it handle consent?
It designs a re-consent action and directs consent outcomes to the consent record workflow.
Does it replace legal advice?
No. Review consent and suppression requirements with qualified legal or compliance professionals.

Developer Details

License

Apache-2.0

Author version

v19.0.0

Skillstore revision

r2

Ref

0715a6e09ea875c8e28cb705ce87cc83045e69c1

Maintenance freshness

7/28/2026

Usage

4 downloads Β· 0 views

File structure

πŸ“„ SKILL.md