Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Compose and send a one-off email to a named recipient via Resend - written in the operator's voice, then sent in-run through the shared send caps with an operator audit copy
.claude/skills/aeonfun-send-email/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-06 | ✗→✓ | ▲ Improved | 574% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 825% | 0% |
| case-16 | ✓→✗ | ▼ Worse | 1264% | 0% |
| case-17 | ✓→✗ | ▼ Worse | 894% | 0% |
| case-21 | ✓→✓ | = Same ✓ | 159% | 0% |
> ${var} — who to email and why, e.g. to=jane@acme.com | subject=Intro | about=propose a 20-min call on X. Freeform also works ("email jane@acme.com to follow up on yesterday's demo"). cc= is optional. The reply-shape revise:<instruction> (Telegram force-reply, e.g. revise:make it warmer) refines the last composed draft for review only — it never sends.
Read soul/ (for voice) and memory/MEMORY.md (for context) before composing.
Composes a single, purposeful email and sends it in-run via Resend (./secretcurl), gated by the shared send caps + kill-switch and logged to the shared ledger memory/email-log.json. The send is irreversible, so it's the skill's final action, behind a set of fail-closed checks (see "Send (in-run)" below): a skipped or failed check means do not send, never send anyway. This is the general-purpose sibling of disclosure-emailer (vuln-scanner Arm C) — same caps + audit CC, any recipient and purpose instead of only vuln maintainers.
This is not a bulk or cold-outreach tool. One deliberate recipient per run, with a genuine reason to write. If the request reads as mass-mailing, list-blasting, or spam, refuse and log SEND_EMAIL_REFUSED: not a 1:1 purposeful email.
Before anything else, if ${var} starts with revise:, the operator replied to a "refine this email?" prompt. Handle it here and end the run — the normal compose/send flow below does NOT run, and nothing is ever sent:
${var#revise:} (keep any inner colons), e.g. make it warmer, shorten to 3 lines, drop the meeting ask.memory/drafts/send-email-latest.md (the review copy the normal run saves in step 4). If it's missing or empty, there's nothing to refine: send ./notify "Nothing to revise yet — compose an email first, then reply here to refine it." and end the run.soul/ for voice; keep the same recipient / cc / subject unless the instruction changes them; keep the body as the exact send-ready text (operator-only notes stay out).memory/drafts/send-email-latest.md with the revised draft. Do NOT run the Send step. A revise: reply never sends — the operator confirms a real send by invoking send-email normally (which re-composes and sends in-run)../notify -f <file>: revised draft (not sent) → <to>: <subject>
<body>
bash ./notify "Want another pass? Reply with a change and I'll revise the draft again (still won't send)." \ --force-reply --placeholder "e.g. make it warmer" \ --context "send-email::revise"
- SEND_EMAIL_REVISED (draft re-staged for review, not sent) under a ### send-email heading in memory/logs/${today}.md, then end the run.Otherwise (no revise: prefix), run the normal flow:
${var}: to (required — one valid email address), optional cc, optional subject, and the about (the goal / what to say). If to or the purpose is missing, check memory/outreach.md for a queued request; if still nothing, log SEND_EMAIL_SKIP: no recipient/purpose and stop.SEND_EMAIL_REFUSED.soul/SOUL.md + soul/STYLE.md; neutral tone if soul is empty). Short, specific, one clear ask or message; add a subject if none was given. The body is exactly what gets sent — keep any reasoning or operator-only notes OUT of it (those live only in the log).memory/drafts/send-email-latest.md (overwrite; mkdir -p memory/drafts). This is the stable path a later revise: reply reloads — it is not the send path, so a revision refines this copy and never re-sends. Set SLUG = recipient-local-part + a short subject hash (the ledger dedup + idempotency key).The send is the skill's final action and is fail-closed: apply every check below in order, and any check that fails, is unset, or errors ⇒ do not send — log the reason and stop. Never fall through to sending. Only ./secretcurl, jq, python3, grep, date, echo, and Write are available; no mv/awk/sha256sum.
$DISCLOSURE_EMAIL_PAUSED is one of 1/true/yes/on → SEND_EMAIL_SKIP: paused, stop.${VAR:+x} form — a bare $RESEND_API_KEY trips the secret-expansion analyzer and falsely reads as unset (same idiom narrative-tracker documents). If either is unset → SEND_EMAIL_SKIP: resend not configured, stop (nothing sent, nothing lost):bash { [ -n "${RESEND_API_KEY:+x}" ] && [ -n "${RESEND_FROM:+x}" ]; } || { echo "SEND_EMAIL_SKIP: resend not configured"; exit 0; }
memory/email-log.json to [] if missing/corrupt, then stop if the count is unreadable (fail closed) or today's budget is spent (cap default 1):bash TODAY=$(date -u +%F) SENT_TODAY=$(jq --arg d "$TODAY" '[.[]|select((.sent_at//"")|startswith($d))]|length' memory/email-log.json 2>/dev/null) case "$SENT_TODAY" in ''|*[!0-9]*) echo "SEND_EMAIL_SKIP: ledger unreadable"; exit 0;; esac [ "$SENT_TODAY" -lt "${DISCLOSURE_EMAIL_DAILY_CAP:-1}" ] || { echo "SEND_EMAIL_SKIP: daily cap"; exit 0; }
bash jq -e --arg s "$SLUG" 'any(.[];.slug==$s)' memory/email-log.json >/dev/null 2>&1 case $? in 0) echo "SEND_EMAIL_SKIP: dup"; exit 0;; 1) : ;; *) echo "SEND_EMAIL_SKIP: ledger unreadable"; exit 0;; esac
$TO must match ^[^@[:space:]]+@[^@[:space:]]+\.[^@[:space:]]+$ (grep -qE) → else SEND_EMAIL_REFUSED: bad recipient, stop.$TO was emailed within ${DISCLOSURE_EMAIL_COOLDOWN_DAYS:-7} days (find its latest .sent_at in the ledger and compare with a python3 datetime diff) → SEND_EMAIL_SKIP: cooldown, stop.grep -qE '(sk-[A-Za-z0-9]{20}|re_[A-Za-z0-9]{8}[A-Za-z0-9_]{12}|gh[pousr]_[A-Za-z0-9]{20}|AKIA[0-9A-Z]{16}|AIza[0-9A-Za-z_-]{20}|-----BEGIN [A-Z ]*PRIVATE KEY-----)' → SEND_EMAIL_BLOCKED: secret in body, stop (never exfiltrate a token).cc (comma-list or array) plus $RESEND_CC (operator audit copy), with blanks and $TO removed and deduped (jq).python3 reading RESEND_FROM/RESEND_REPLY_TO from os.environ — so no secret-named var ever lands on a command line (a --arg from "$RESEND_FROM" would risk the analyzer block). Then POST with ./secretcurl (the {RESEND_API_KEY} header placeholder is substituted inside the script; $PAYLOAD carries only the already-resolved from-address, not a secret-named expansion). slug is the idempotency key so a re-run can't double-send:bash PAYLOAD=$(python3 - "$TO" "$SUBJECT" "$BODY" "$CC_JSON" <<'PY' import os, sys, json to, subject, text, cc = sys.argv[1], sys.argv[2], sys.argv[3], json.loads(sys.argv[4] or "[]") p = {"from": os.environ["RESEND_FROM"], "to": [to], "subject": subject, "text": text} if os.environ.get("RESEND_REPLY_TO"): p["reply_to"] = os.environ["RESEND_REPLY_TO"] if cc: p["cc"] = cc print(json.dumps(p)) PY ) ./secretcurl -sS --max-time 30 -w 'http=%{http_code}\n' -X POST "https://api.resend.com/emails" \ -H "Authorization: Bearer {RESEND_API_KEY}" -H "Content-Type: application/json" \ -H "Idempotency-Key: $SLUG" -d "$PAYLOAD" Print http=<code>. A response body with .id = sent; no .id (or non-2xx) = failed → SEND_EMAIL_FAILED: <message>, stop (it's a one-off — nothing to retry).
memory/email-log.json (via python3 read-modify-write or the Write tool — there is no mv): {slug:$SLUG, to:$TO, subject:$SUBJECT, resend_id:<id>, sent_at:<date -u +%FT%TZ>}../notify: email sent → <to>: <subject> Then offer a revision — a separate ./notify (dedup: once per produced draft — scan the last ~2 days of memory/logs/ for a FORCE_REPLY_OFFERED: revise line dated ${today} and skip if present): bash ./notify "Want to refine this email? Reply with a change and I'll revise the draft (won't re-send)." \ --force-reply --placeholder "e.g. make it warmer" \ --context "send-email::revise" The reply routes back as var="revise:<instruction>" → the Revise intercept above, which re-stages the draft for review only and never sends. Note: the email was already sent in-run (step "Send"), so this offer refines the review copy for the operator's records — any real re-send is a fresh normal invocation, not a change to the message that already went out.
memory/logs/${today}.md: ### send-email
If you sent the revision offer, also append - FORCE_REPLY_OFFERED: revise.
./secretcurl ({RESEND_API_KEY} placeholder — a bare $RESEND_API_KEY on the line is refused by the Bash permission layer). It is the skill's last action, behind the fail-closed checks in "Send (in-run)". There is no deferred/postprocess step: a failed send stays failed (log SEND_EMAIL_FAILED), it is not queued for later.disclosure-emailer = vuln-scanner Arm C)RESEND_API_KEY, RESEND_FROM (verified sender), RESEND_REPLY_TO — injected in-run via this skill's requires:. RESEND_CC (operator audit copy) is a repo var bound in the run env.memory/email-log.json, so this skill and disclosure-emailer share one daily budget: DISCLOSURE_EMAIL_DAILY_CAP (default 1 — raise for more outreach), DISCLOSURE_EMAIL_COOLDOWN_DAYS, and the kill-switch DISCLOSURE_EMAIL_PAUSED.Other measured skills in the registry, with their headline benchmark lift.