Agent skill

E Signature

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when wiring an e-signature flow with DocuSign or Dropbox Sign — picking the SES/AES/QES legal tier, sending a PDF or template for signature, embedded signing, verifying…

MITAuto-check passedDocuments & Office

Install E Signature

skills CLI
$ npx skills add ericrisco/rsc-harness --skill e-signature -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness e-signature --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/e-signature .claude/skills/e-signature && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
e-signature
GitHub stars
180
Token cost
~3k tokens
SKILL.md length
1,168 words
Files
7 (incl. scripts, references)
Skills in repo
233
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when wiring an e-signature flow with DocuSign or Dropbox Sign — picking the SES/AES/QES legal tier, sending a PDF or template for signature, embedded signing, verifying…

  • Works in 5 steps: Create the integration key + RSA keypair… → Grant one-time consent: visit the… → Request a JWT user token (scope:… → …
  • Wiring an e-signature flow with DocuSign
  • SKILL.md covers Decision: which legal tier do…, Decision: which provider?, Auth & setup and Send flow — DocuSign, plus 5 more sections
  • Runs Shell scripts from its folder; reaches demo.docusign.net and docusign.net; needs DROPBOX_SIGN_API_KEY and DOCUSIGN_INTEGRATION_KEY

What it does

E Signature is an agent skill from ericrisco/rsc-harness. Use when wiring an e-signature flow with DocuSign or Dropbox Sign — picking the SES/AES/QES legal tier, sending a PDF or template for signature, embedded signing, verifying signing webhooks, retrieving the signed PDF plus audit trail. NOT drafting contract text (that is contracts), NOT extracting fields from PDFs (that is document-processing).

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/docusign.md`).

It sits in Documents & Office, covering PDF and Webhooks. It works with Dropbox. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Wiring an e-signature flow with DocuSign
  • Dropbox Sign — picking the SES/AES/QES legal tier
  • Template for signature
  • Embedded signing

Example prompts

  • “/e-signature”

Requirements

  • A Bash shell
  • A credential in DOCUSIGN_INTEGRATION_KEY
  • A credential in DOCUSIGN_PRIVATE_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Create the integration key + RSA keypair in the DocuSign admin console.
  2. Grant one-time consent: visit the consent URL once as the impersonated user (.../oauth/auth?response_type=code&scope=signature%20impersonat…
  3. Request a JWT user token (scope: signature impersonation), signed with the RSA private key.
  4. Call /oauth/userinfo to discover the account's correct base path — do not hardcode the prod host while testing.
  5. Use the returned access token + base path for all API calls; refresh before expiry.

What it can do on your machine

Read from SKILL.md and the folder at commit 1f8d9bb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • demo.docusign.net
    • docusign.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DROPBOX_SIGN_API_KEY
    • DOCUSIGN_INTEGRATION_KEY
    • DOCUSIGN_PRIVATE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

E Signature loads about 3k tokens when it runs, and up to ~5.6k if it reads all its reference files. Until then it costs about 90 tokens; SKILL.md has 1,168 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 1f8d9bb, republished under its MIT licence (© ericrisco). 1,168 words, ~2,993 tokens.

Download SKILL.mdSave it as .claude/skills/e-signature/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
e-signature
description
Use when wiring an e-signature flow with DocuSign or Dropbox Sign — picking the SES/AES/QES legal tier, sending a PDF or template for signature, embedded signing, verifying signing webhooks, retrieving the signed PDF plus audit trail. NOT drafting contract text (that is `contracts`), NOT extracting fields from PDFs (that is `document-processing`).
tags
e-signature, docusign, dropbox-sign, esignature-api, webhooks, eidas, esign-act, audit-trail
recommends
contracts, document-processing, webhooks, api-connector-builder, gdpr-privacy, automation-flows
origin
risco

e-signature

You are wiring a third-party signing API (DocuSign eSignature or Dropbox Sign, ex-HelloSign) into someone's app or backend. You take a PDF or template, define signers and fields, send it for signature, track status, react to completion via a verified webhook, and retrieve the signed PDF plus its audit trail.

Contract language — clauses, indemnity, liability — goes to ../contracts/SKILL.md; OCR, field extraction, or PDF splitting with no signing involved is ../document-processing/SKILL.md.

Pick the tier deliberately, before you write code: it decides which provider features you enable (ID Verification, SMS/access code, qualified signature), and getting it wrong leaves a signature that is hard to defend in court.

US law (ESIGN Act + UETA) has no tiers — e-signatures equal wet ink. The EU (eIDAS, and eIDAS 2.0 / Reg (EU) 2024/1183 in force since May 2024) defines three. A typed name (SES) is binding for most B2B in the US and EU, but a high-stakes EU document may need AES or QES. Map the document's stakes to a tier, then to a provider feature.

TierWhat it isWhen you need itProvider feature to enable
SES (Simple)Typed or drawn signature, basic intent + audit trailMost B2B: offers, NDAs, quotes, US contracts generallyDefault flow — just capture the signature + keep the audit trail
AES (Advanced)Uniquely linked to signer, identity-verified, tamper-evidentHigher-value EU contracts, regulated sectorsID Verification, SMS/access-code auth, signer authentication step
QES (Qualified)EU handwritten-equivalent EU-wide; qualified cert via a QTSPWhere law mandates it (some real-estate, gov, regulated finance)Qualified signature add-on through a Qualified Trust Service Provider

If the document is genuinely high-stakes or you are unsure whether a tier is legally mandated, escalate to a lawyer and to ../contracts/SKILL.md — you do not give legal advice. Detail and the court-admissibility checklist live in references/legal-tiers.md.

Decision: which provider?

Either is fine. Pick one and stay on it so you keep one consistent audit trail.

DocuSign eSignatureDropbox Sign (ex-HelloSign)
AuthOAuth 2.0 JWT Grant (RSA keypair, impersonation, one-time consent)API key (header bearer)
Core callcreate Envelopesignature_request/send
Node SDKdocusign-esign (9.0.0)@dropbox/sign (1.11.0) — replaces deprecated hellosign-sdk
EmbeddedclientUserId on recipient + recipient view URLsignature_request/create_embedded
Pricing postureseat/envelope, enterprise-leaningAPI: Essentials ~$75/mo (50+ requests, embedded signing included), Standard ~$250/mo annual (adds bulk send + higher volume), free test_mode
EU / QESmature QES + ID VerificationSES/AES focus; check current QES support

Auth & setup

Never commit keys. Read everything from env; the RSA private key lives in a secret store or a file path, never inline in source.

Point at the sandbox before prod, always — a live send is billable and emails a real human. DocuSign demo env is https://demo.docusign.net; Dropbox Sign uses test_mode: 1. Only non-test sends count against quota and reach signers.

Env varProviderHolds
DOCUSIGN_INTEGRATION_KEYDocuSignclient/integration key (GUID)
DOCUSIGN_USER_IDDocuSignGUID of the user being impersonated
DOCUSIGN_ACCOUNT_IDDocuSignAPI account ID
DOCUSIGN_PRIVATE_KEYDocuSignRSA private key (PEM) — from secret store
DOCUSIGN_BASE_PATHDocuSignhttps://demo.docusign.net/restapi in sandbox
DROPBOX_SIGN_API_KEYDropbox SignAPI key

DocuSign JWT Grant — five steps (full walk-through in references/docusign.md):

  1. Create the integration key + RSA keypair in the DocuSign admin console.
  2. Grant one-time consent: visit the consent URL once as the impersonated user (.../oauth/auth?response_type=code&scope=signature%20impersonation&client_id=...&redirect_uri=...).
  3. Request a JWT user token (scope: signature impersonation), signed with the RSA private key.
  4. Call /oauth/userinfo to discover the account's correct base path — do not hardcode the prod host while testing.
  5. Use the returned access token + base path for all API calls; refresh before expiry.

Dropbox Sign needs only the API key as a bearer credential — see references/dropbox-sign.md.

bash
# Bad: key in source, prod host while testing
const apiKey = "hs_live_abc123";          # committed secret
const base   = "https://www.docusign.net"; # prod during a test

# Good: from env, sandbox first
export DROPBOX_SIGN_API_KEY="$(op read op://vault/dropbox-sign/key)"
export DOCUSIGN_BASE_PATH="https://demo.docusign.net/restapi"

Send flow — DocuSign

The core object is an Envelope. status: "sent" sends immediately; status: "created" saves a draft. Anchor strings let you place tabs by text in the PDF instead of fixed coordinates.

javascript
import docusign from "docusign-esign";

const env = {
  emailSubject: "Please sign: Offer letter",
  documents: [{
    documentBase64: pdfBuffer.toString("base64"),
    name: "Offer.pdf", fileExtension: "pdf", documentId: "1",
  }],
  recipients: {
    signers: [{
      email: signer.email, name: signer.name,
      recipientId: "1", routingOrder: "1",
      tabs: { signHereTabs: [{ anchorString: "/sig1/", anchorYOffset: "-10" }] },
    }],
  },
  status: "sent", // "created" for a draft you send later
};

const api = new docusign.EnvelopesApi(apiClient); // apiClient configured with JWT token + base path
const result = await api.createEnvelope(accountId, { envelopeDefinition: env });
// store result.envelopeId — your handle for status, webhook correlation, and retrieval

For templates, send with templateId + templateRoles (prefilled tabs) instead of raw documents. Envelope/tabs anatomy and template send are in references/docusign.md.

Send flow — Dropbox Sign

The core call is signature_request/send (or signature_request/send_with_template). Keep testMode: true until you intend to spend a real request.

javascript
import * as DropboxSign from "@dropbox/sign";

const api = new DropboxSign.SignatureRequestApi();
api.username = process.env.DROPBOX_SIGN_API_KEY; // API key as username

const res = await api.signatureRequestSend({
  title: "Offer letter",
  subject: "Please sign",
  signers: [{ emailAddress: signer.email, name: signer.name, order: 0 }],
  files: [pdfBuffer], // or fileUrls
  testMode: true, // flip to false ONLY when going live
});
// store res.body.signatureRequest.signatureRequestId

send_with_template takes templateIds + signers mapped to template roles. Details and embedded creation are in references/dropbox-sign.md.

Show full SKILL.md (483 more words)Show less

Embedded vs remote signing

  • Remote (default): provider emails the signer a link. Nothing extra to build.
  • Embedded (signer signs inside your own UI): DocuSign requires a clientUserId on the recipient, then you request a recipient view URL and iframe/redirect to it. Dropbox Sign uses signature_request/create_embedded + the embedded sign URL. Embedded signing is included from the Dropbox Sign Essentials API plan up (it is not a Standard-only feature) — but it still requires a paid API plan, not test_mode alone.

Webhooks / completion

A send is not done when status is sent — it is done when the signer completes and you have pulled the signed document AND its evidence (DocuSign Certificate of Completion, Dropbox Sign audit-trail PDF), retrieved and stored. Fire-and-forget is the most common bug here.

Verify the signature before you trust anything in the payload. The body is attacker-controllable until you have verified it.

  • DocuSign Connect: HMAC-signed; verify the X-DocuSign-Signature-1 header against the raw request body using your Connect HMAC key.
  • Dropbox Sign event callbacks: event_hash = HMAC-SHA256 of event_time + event_type, keyed by your API key.
javascript
import crypto from "node:crypto";

// Dropbox Sign: verify event_hash before processing
function verifyDropboxSign(event, apiKey) {
  const expected = crypto
    .createHmac("sha256", apiKey)
    .update(event.event.event_time + event.event.event_type)
    .digest("hex");
  return crypto.timingSafeEqual(
    Buffer.from(expected), Buffer.from(event.event.event_hash));
}

// On a verified completion event: retrieve BOTH artifacts, idempotently
async function onCompleted(requestId) {
  if (await alreadyHandled(requestId)) return;     // idempotency guard
  const signedPdf  = await api.signatureRequestFiles(requestId, "pdf");
  const auditTrail = await api.signatureRequestFiles(requestId, "pdf", { fileType: "audit" });
  await store(requestId, signedPdf, auditTrail);   // store IDs + bytes, never log bytes
  await markHandled(requestId);
}

For DocuSign, on the Completed envelope event call EnvelopesApi.getDocument for the signed PDF and for certificate to get the Certificate of Completion. HMAC verification code and Connect setup are in references/docusign.md.

Anti-patterns

Anti-patternWhy it is wrongDo instead
Processing a webhook payload without verifying the signatureAnyone can POST a fake completed eventVerify HMAC (X-DocuSign-Signature-1 / event_hash) on the raw body first
Trusting status from the request body you sentStatus lives with the provider, not your hopeRead status from the verified webhook or a status fetch
Sending from prod while still testingBills you and emails real people with test docsDocuSign demo.docusign.net; Dropbox Sign testMode: true
Logging full document/envelope bytes or signer PIILeaks the very PII the signature protectsLog provider IDs only; store bytes in a secret-aware store
Storing the signed PDF but not the audit trailSES is hard to defend in court without who/what/when/whereAlways pull the Certificate of Completion / audit-trail PDF too
Reusing one envelope/request to "retry" a sendDuplicates, double-bills, corrupts statusNew request per send; use an idempotency guard on completion
Hardcoding the API key / RSA private key in sourceSecret leak on first pushEnv vars + secret store; key file path, never inline
Skipping the legal-tier decisionShip a signature that is not legally adequatePick SES/AES/QES first; escalate high-stakes to a lawyer + ../contracts/SKILL.md

Verify

Run scripts/verify.sh <path-to-integration> against the code you produced. It greps the artifact (no live API call) for: webhook signature verification present and not a TODO, no hardcoded API key or BEGIN PRIVATE KEY, a sandbox/test_mode guard, and a completion path that retrieves the signed PDF + audit trail. It is read-only and exits 0 on a clean/empty target.

For data-protection touchpoints (consent, retention of signed docs + PII), flag them and route the policy writing to ../gdpr-privacy/SKILL.md. For non-signing inbound webhook infrastructure, see ../webhooks/SKILL.md.

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in skills/e-signature of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/docusign.md
  • references/dropbox-sign.md
  • references/legal-tiers.md
  • scripts/verify.sh

Open the folder on GitHubat commit 1f8d9bb

Compare with similar skills

E Signature next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

E Signature compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
E Signature this skillericrisco/rsc-harness180—~3kAutomated safety check: PassMIT
Build With SimplepdfSimplePDF/simplepdf-embed407—~7kAutomated safety check: PassMIT
Google Apps Scriptjezweb/claude-skills1.1k—~4.7kAutomated safety check: PassMIT
Investigate Dropbox Sync Issueblotcms/blot2k—~4.7kAutomated safety check: PassAGPL-3.0
Fullenrich Network ActivationOthmane-Khadri/YALC-the-GTM-operating-system318—~1.1kAutomated safety check: WarnMIT
Bio Reporting Rmarkdown ReportsGPTomics/bioSkills1.2k1 repos~2.1kAutomated safety check: PassMIT

Similar skills

  • Build With Simplepdf

    SimplePDF/simplepdf-embed

    Integrate SimplePDF into a web application for PDF viewing, editing, filling, signing, programmatic control, AI-agent interaction, human-in-the-loop form prefilling, submissions, webhooks, or…

    407 GitHub stars~7k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Google Apps Script

    jezweb/claude-skills

    Build Google Apps Script automation for Sheets and Workspace.

    1.1k GitHub stars~4.7k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Investigate a "Dropbox sync issue" alert email from Blot's hourly Dropbox sync validation (each flagged blog lists unsynced changes, Fix() repairs, errors and/or a stuck folder lock; the changes…

    2k GitHub stars~4.7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Fullenrich Network Activation

    Othmane-Khadri/YALC-the-GTM-operating-system

    A skill your agent uses when the user says "activate co-founder network with FullEnrich", "enrich LinkedIn connections export", "qualify my LinkedIn connections CSV", "turn Connections.csv into a…

    318 GitHub stars~1.1k tokensUpdated 1 mo ago
    Documents & OfficeAuto-check: warnings
  • Creates reproducible R Markdown analysis reports (HTML, PDF, Word) with knitr, covering the render pipeline, the interactive-vs-knit session trap, cache invalidation, bookdown cross-references…

    1.2k GitHub starsUsed in 1 repo~2.1k tokens
    Documents & OfficeAuto-check passed
  • Frappe Impl Jinja

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when building Jinja templates in Frappe: Print Formats, Email Templates, Notification templates, Portal Pages, and custom Jinja methods.

    189 GitHub stars~3.6k tokensUpdated 23 days ago
    Documents & OfficeAuto-check passed

More from ericrisco/rsc-harness

All 233 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    180 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    180 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    180 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    180 GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    180 GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    180 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about E Signature

What does E Signature do?

A skill your agent uses when wiring an e-signature flow with DocuSign or Dropbox Sign — picking the SES/AES/QES legal tier, sending a PDF or template for signature, embedded signing, verifying…. E Signature is an agent skill from ericrisco/rsc-harness. Use when wiring an e-signature flow with DocuSign or Dropbox Sign — picking the SES/AES/QES legal tier, sending a PDF or template for signature, embedded signing, verifying signing webhooks, retrieving the signed PDF plus audit trail.

When should I use E Signature?

E Signature fits situations like: wiring an e-signature flow with DocuSign; dropbox Sign — picking the SES/AES/QES legal tier; template for signature; embedded signing.

How do I install E Signature in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill e-signature -a claude-code`. Or copy the skill folder (skills/e-signature in ericrisco/rsc-harness) into .claude/skills/e-signature in your project. Claude Code loads it when a task matches its description.

How do I install E Signature in Codex?

Run `npx skills add ericrisco/rsc-harness --skill e-signature -a codex`. Or copy the skill folder (skills/e-signature in ericrisco/rsc-harness) into .agents/skills/e-signature in your project. Codex loads it when a task matches its description.

Can I use E Signature in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill e-signature -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/e-signature, .gemini/skills/e-signature, .github/skills/e-signature and .opencode/skills/e-signature in your project.

What does E Signature need to run?

Going by SKILL.md and its folder, E Signature needs a shell for the scripts in its folder and credentials named DROPBOX_SIGN_API_KEY, DOCUSIGN_INTEGRATION_KEY and DOCUSIGN_PRIVATE_KEY. Our summary lists: A Bash shell; A credential in DOCUSIGN_INTEGRATION_KEY; A credential in DOCUSIGN_PRIVATE_KEY.

Does E Signature access the network?

SKILL.md names 2 domains. In commands or code: demo.docusign.net and docusign.net; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is E Signature safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does E Signature use?

E Signature is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does E Signature use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.

What are the alternatives to E Signature?

Skills that share tags, products or a category with E Signature: Build With Simplepdf (SimplePDF/simplepdf-embed, 407 stars), Google Apps Script (jezweb/claude-skills, 1.1k stars), Investigate Dropbox Sync Issue (blotcms/blot, 2k stars) and Fullenrich Network Activation (Othmane-Khadri/YALC-the-GTM-operating-system, 318 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains E Signature?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 180 GitHub stars. The repository holds 233 skills in this directory. The repository was last updated on October 9, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.