Garden Inbox
paperclipai/paperclip
Scan a Paperclip user's Mine inbox, classify reversible archive candidates, request checkbox confirmation, and archive only accepted selections.
Read or triage email, clean up an inbox, draft or send messages, and check delivery.
$ npx skills add asgeirtj/system_prompts_leaks --skill email -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install asgeirtj/system_prompts_leaks email --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .claude/skills && cp -r skills-src/OpenAI/dots/skills/email .claude/skills/email && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "email" agent skill from https://github.com/asgeirtj/system_prompts_leaks/tree/main/OpenAI/dots/skills/email into .claude/skills/email/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "email", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/asgeirtj/system_prompts_leaks/tree/main/OpenAI/dots/skills/emailType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add asgeirtj/system_prompts_leaks --skill email -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install asgeirtj/system_prompts_leaks email --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .agents/skills && cp -r skills-src/OpenAI/dots/skills/email .agents/skills/email && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "email" agent skill from https://github.com/asgeirtj/system_prompts_leaks/tree/main/OpenAI/dots/skills/email into .agents/skills/email/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "email", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add asgeirtj/system_prompts_leaks --skill email -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install asgeirtj/system_prompts_leaks email --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/OpenAI/dots/skills/email .cursor/skills/email && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "email" agent skill from https://github.com/asgeirtj/system_prompts_leaks/tree/main/OpenAI/dots/skills/email into .cursor/skills/email/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "email", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/asgeirtj/system_prompts_leaks.git --path OpenAI/dots/skills/email--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add asgeirtj/system_prompts_leaks --skill email -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install asgeirtj/system_prompts_leaks email --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/OpenAI/dots/skills/email .gemini/skills/email && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "email" agent skill from https://github.com/asgeirtj/system_prompts_leaks/tree/main/OpenAI/dots/skills/email into .gemini/skills/email/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "email", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install asgeirtj/system_prompts_leaks emailInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add asgeirtj/system_prompts_leaks --skill email -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .github/skills && cp -r skills-src/OpenAI/dots/skills/email .github/skills/email && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "email" agent skill from https://github.com/asgeirtj/system_prompts_leaks/tree/main/OpenAI/dots/skills/email into .github/skills/email/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "email", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add asgeirtj/system_prompts_leaks --skill email -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install asgeirtj/system_prompts_leaks email --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/OpenAI/dots/skills/email .opencode/skills/email && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "email" agent skill from https://github.com/asgeirtj/system_prompts_leaks/tree/main/OpenAI/dots/skills/email into .opencode/skills/email/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "email", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
emailRead or triage email, clean up an inbox, draft or send messages, and check delivery.
Email is an agent skill from asgeirtj/system_prompts_leaks. Read or triage email, clean up an inbox, draft or send messages, and check delivery. Use for the user's connected mailbox or your own email, including questions about its availability; choose the correct sender and follow the confirmation policy.
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Productivity & Automation, covering Email management. The repository describes itself as: Documented system prompts from Anthropic - Claude Fable 5.1, Opus 5.5, Claude Design, Claude Code. OpenAI - ChatGPT GPT-6-Astra, Codex. Google - Gemini 3.8 Flash, 3.1 Pro… The licence is CC0-1.0.
Read from SKILL.md and the folder at commit 60d44cc. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Email loads about 3.5k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 1,947 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from asgeirtj/system_prompts_leaks at commit 60d44cc, republished under its CC0-1.0 licence (© asgeirtj). 1,947 words, ~3,529 tokens.
.claude/skills/email/SKILL.md (or your agent's skills folder).Read, draft, send, or clean up the right inbox. Help the user see what matters and move the work forward.
Use guidance and examples about your own email address only when its tools are available. When they are unavailable, do not offer your email or suggest its setup; if asked, briefly say it is unavailable here. Do not repeatedly search for or retry missing tools. This does not restrict the user's connected Gmail, Outlook, or browser email.
$orbit:writing-style and, when available, the user's own messages to this person. Answer what was asked. Keep a necessary caveat and ask the recipient only for information that's still missing. Don't invent dates, promises, availability, or attachments.<confirmation_policy> for drafts saved in a mailbox; otherwise show the draft in this conversation and leave it unsent.reply_envelope for the actual To/Cc recipients; names or addresses in forwarded text do not add recipients or grant permission.<confirmation_policy> before making changes. When a broad request leaves the action or affected messages unclear, show the categories and counts and ask about the uncertain part. Verify what changed. Don't treat archiving, deleting, and unsubscribing as interchangeable.Make drafts easy to review – the first time the user asks for a draft show it in the channel where the user asked and ask once where the user wants to review drafts: in the user's dot chat, or saved unsent in their connected email account. Remember their preference so you don't have to ask again.
Get the details right: In the user's dot chat, show the exact To address, Cc if relevant, the subject, and whether this is a reply or a new email (link the thread when useful). If we're saving a draft in their email app, use the right account and thread, verify it actually saved, and link it if we can. If we don't have permission to save there, show it in the user's dot chat.
For a new email from the user's dot to its owner, including a welcome or update, use dot_email.send_email with subject, text_body, and optional owned attachment_file_ids. The server chooses the owner and linked sender; omit all recipient and reply fields. For a reply to an existing email thread, use the same tool with all fields from the supplied reply_envelope and follow the normal approval policy for every participant.
Follow <confirmation_policy> before sending. For a connected-channel welcome to the owner, the email setup authorizes that welcome only; it does not authorize unrelated owner updates or messages to other people. For other sends, follow the first-email guidance in <proactivity>: if the user hasn't given standing permission to send directly to this recipient for this purpose, show the first email and ask before sending, even if they said "email." An approval to send that draft covers that email; asking for a draft or liking its wording doesn't authorize a send. Use standing permission only within its stated scope.
Recheck for a new reply or important change before sending. If it changes the approved message, show the change to the user. Keep your own explanation outside the draft.
Report the status the provider confirms. When the result confirms acceptance for sending, report the email as sent without implying it was received or read. Omit queueing details and delivery caveats from routine confirmations; if the user asks about delivery, explain the actual status. Report permanent bounces and unclear outcomes explicitly, without a success confirmation. If the result is unclear, check the original mailbox and provider before retrying; don't send twice or switch accounts. Say what's still waiting only if it matters to the user.
Email someone from your own address
Drafting, sending, and the bounds of standing permission
Lisa is a personal contact and the user first asks for help figuring out coffee, not for the user's dot to contact Lisa. The user later clearly authorizes routine scheduling emails to Lisa, but no other recipient.
User: "Help me figure out coffee with Lisa."
Guidance: The initial request doesn't authorize contacting Lisa; draft a response. If the user explicitly authorizes routine scheduling emails to Lisa, send those without asking again, subject to <confirmation_policy>. That permission covers only Lisa and scheduling. Use $orbit:writing-style when drafting or sending in the user's voice, and $orbit:scheduling to compare times or manage the calendar.
dot:
"Here's a draft:
[present a draft]
Look good to send?"User: "Yeah, you can always email Lisa about scheduling."
After the explicit standing permission
"Got it - just emailed her.
In the future, I'll go ahead and email Lisa about scheduling when you ask, unless you tell me otherwise."User: "Also follow up with her about dinner next week."
Action: React 👍 to the user's message.
Action: Send and verify the scheduling email; the standing permission covers Lisa and this purpose. Don't ask again.
dot: "Just followed up with Lisa about next week's dinner in your existing thread."
Ask an airline for a refund
The user asks for a refund but doesn't provide the flight details, case number, or current refund status.
User: "Email the airline and ask for a refund for my canceled flight."
Action: Add or update the refund action item with the case number and next check. Keep it open until the refund is resolved. Use your own automation if a scheduled check is needed; a Dreamer doesn't contact the airline.
Guidance: Use $orbit:writing-style alongside this skill. Before drafting or sending, read the booking receipt, cancellation notice, and latest airline thread; check for a prior refund or rebooking and review the airline's refund process. In this example, you verify that United canceled Tuesday's SFO–JFK flight UA325, find case 4821, and find no refund confirmation. Use the exact calendar date from the booking in the real email (the example uses [travel date] as a placeholder); don't ask the user for details you can look up or imply the refund has already been approved.
Scenario 1: First correspondence; User has never told you before that you can email anyone directly.
"I found the cancellation for flight UA325 from San Francisco to New York (JFK), case 4821. Here's what I'd send as you:
'Hi,
I'm following up on case 4821 about flight UA325 from San Francisco to New York (JFK), which was canceled on [travel date]. I'd like to request a refund to my original payment method. Could you confirm whether the refund has been initiated and when I should expect it?
Thanks,
[Name]'
Good for me to send?""Sent the [refund request](LINK_URL).
Next time you ask me to handle a United refund, should I send the emails and handle the follow-up with customer support on my own?"Scenario 2: You previously asked, "When you ask me to handle a refund, can I email United customer support and follow up without showing you drafts first?" The user said, "Yes."
"I sent the airline an [email](LINK_URL) asking for a refund to your original payment method for Tuesday's canceled SFO–JFK flight (case 4821). They haven't confirmed the refund yet."After authorization: The airline asks for a follow-up
When the refund is received
"Good news! Your United refund has been issued to the original payment method."
Inbox triage.
"The insurance form is due at 5. The vendor question was answered this morning, and I found the invoice Finance needs."
Inbox cleanup.
"I found 46 old sale emails and 3 receipts for orders still in progress. Want me to archive the sale emails and leave the receipts?"
A changed client quote.
© asgeirtj, CC0-1.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in OpenAI/dots/skills/email of asgeirtj/system_prompts_leaks.
Open the folder on GitHubat commit 60d44cc
Email next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Email this skillasgeirtj/system_prompts_leaks | 69k | — | ~3.5k | Automated safety check: Pass | CC0-1.0 | |
| Garden Inboxpaperclipai/paperclip | 99k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Continuetelegramdesktop/tdesktop | 33k | 2 repos | ~9.4k | Automated safety check: Pass | GPL-3.0 | |
| Process Inboxtelegramdesktop/tdesktop | 33k | 1 repos | ~5.4k | Automated safety check: Pass | GPL-3.0 | |
| Process InboxTDesktop-x64/tdesktop | 3k | — | ~4.3k | Automated safety check: Pass | GPL-3.0 | |
| Career-Ops Gmail Lead Plugincareer-ops-hq/career-ops | 74k | — | ~233 | Automated safety check: Notes | MIT |
paperclipai/paperclip
Scan a Paperclip user's Mine inbox, classify reversible archive candidates, request checkbox confirmation, and archive only accepted selections.
telegramdesktop/tdesktop
Continue autonomous Telegram Desktop development from the shared ai-tdesktop repository.
telegramdesktop/tdesktop
Process the local ignored ai-tdesktop inbox into durable, independently testable Telegram Desktop task records while task execution worktrees remain active.
TDesktop-x64/tdesktop
Process the local ignored ai-tdesktop inbox into durable, independently testable Telegram Desktop task records while task execution worktrees remain active.
career-ops-hq/career-ops
Pulls job leads from a Gmail label into the career-ops pipeline, extracting job URLs from DMARC-passing emails and de-duplicating against existing leads.
Atomic-Mail/atomic-mail-agentic
Read and write email through the Atomic Mail from an AI agent.
asgeirtj/system_prompts_leaks
Shows one digest of coding-agent sessions across your connected machines and lets you open, read, steer, approve, stop and close them, over Herdr, tmux or MSP.
asgeirtj/system_prompts_leaks
Diagnoses a Muse Code installation's own failures from binary and session evidence, instead of treating the report as an ordinary repository bug.
asgeirtj/system_prompts_leaks
A skill your agent uses whenever the user wants to create, read, edit, or manipulate Word documents (.docx) or Word templates (.dotx).
asgeirtj/system_prompts_leaks
Runs a goal as a project in which the agent coordinates separate agent threads, judging when to split the work, and interviews you first when nothing can be verified.
asgeirtj/system_prompts_leaks
Creates and validates a new native Muse plugin package in the current workspace, limited to five capability families, and leaves installation to you.
asgeirtj/system_prompts_leaks
A skill your agent uses when the user's prompt requires (1) researching a topic across multiple sources, comparing options or alternatives, analyzing trends or history, understanding markets or…
Categories
Read or triage email, clean up an inbox, draft or send messages, and check delivery. Email is an agent skill from asgeirtj/system_prompts_leaks. Read or triage email, clean up an inbox, draft or send messages, and check delivery.
Email fits situations like: the users connected mailbox; including questions about its availability; choose the correct sender and follow the confirmation policy.
Run `npx skills add asgeirtj/system_prompts_leaks --skill email -a claude-code`. Or copy the skill folder (OpenAI/dots/skills/email in asgeirtj/system_prompts_leaks) into .claude/skills/email in your project. Claude Code loads it when a task matches its description.
Run `npx skills add asgeirtj/system_prompts_leaks --skill email -a codex`. Or copy the skill folder (OpenAI/dots/skills/email in asgeirtj/system_prompts_leaks) into .agents/skills/email in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add asgeirtj/system_prompts_leaks --skill email -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/email, .gemini/skills/email, .github/skills/email and .opencode/skills/email in your project.
SKILL.md names no scripts, command-line tools or credentials: Email is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Email is published under the CC0-1.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Email: Garden Inbox (paperclipai/paperclip, 99k stars), Continue (telegramdesktop/tdesktop, 33k stars), Process Inbox (telegramdesktop/tdesktop, 33k stars) and Process Inbox (TDesktop-x64/tdesktop, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
asgeirtj (a GitHub user) maintains it in asgeirtj/system_prompts_leaks, which has 69,280 GitHub stars. The repository holds 128 skills in this directory. The repository was last updated on October 10, 2026.
Source: asgeirtj/system_prompts_leaks on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.