Build With Simplepdf
SimplePDF/simplepdf-embed
Integrate SimplePDF into a web application for PDF viewing, editing, filling, signing, programmatic control, AI-agent interaction, human-in-the-loop form prefilling, submissions, webhooks, or…
A skill your agent uses when wiring an e-signature flow with DocuSign or Dropbox Sign — picking the SES/AES/QES legal tier, sending a PDF or template for signature, embedded signing, verifying…
$ npx skills add ericrisco/rsc-harness --skill e-signature -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness e-signature --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/e-signature .claude/skills/e-signature && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "e-signature" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/e-signature into .claude/skills/e-signature/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "e-signature", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/e-signatureType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill e-signature -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness e-signature --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/e-signature .agents/skills/e-signature && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "e-signature" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/e-signature into .agents/skills/e-signature/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "e-signature", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill e-signature -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness e-signature --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/e-signature .cursor/skills/e-signature && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "e-signature" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/e-signature into .cursor/skills/e-signature/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "e-signature", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/e-signature--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill e-signature -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness e-signature --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/e-signature .gemini/skills/e-signature && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "e-signature" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/e-signature into .gemini/skills/e-signature/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "e-signature", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness e-signatureInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill e-signature -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/e-signature .github/skills/e-signature && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "e-signature" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/e-signature into .github/skills/e-signature/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "e-signature", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill e-signature -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness e-signature --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/e-signature .opencode/skills/e-signature && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "e-signature" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/e-signature into .opencode/skills/e-signature/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "e-signature", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
e-signatureA skill your agent uses when wiring an e-signature flow with DocuSign or Dropbox Sign — picking the SES/AES/QES legal tier, sending a PDF or template for signature, embedded signing, verifying…
E Signature is an agent skill from ericrisco/rsc-harness. Use when wiring an e-signature flow with DocuSign or Dropbox Sign — picking the SES/AES/QES legal tier, sending a PDF or template for signature, embedded signing, verifying signing webhooks, retrieving the signed PDF plus audit trail. NOT drafting contract text (that is contracts), NOT extracting fields from PDFs (that is document-processing).
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/docusign.md`).
It sits in Documents & Office, covering PDF and Webhooks. It works with Dropbox. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1f8d9bb. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
demo.docusign.netdocusign.netFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DROPBOX_SIGN_API_KEYDOCUSIGN_INTEGRATION_KEYDOCUSIGN_PRIVATE_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
E Signature loads about 3k tokens when it runs, and up to ~5.6k if it reads all its reference files. Until then it costs about 90 tokens; SKILL.md has 1,168 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit 1f8d9bb, republished under its MIT licence (© ericrisco). 1,168 words, ~2,993 tokens.
.claude/skills/e-signature/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.You are wiring a third-party signing API (DocuSign eSignature or Dropbox Sign, ex-HelloSign) into someone's app or backend. You take a PDF or template, define signers and fields, send it for signature, track status, react to completion via a verified webhook, and retrieve the signed PDF plus its audit trail.
Contract language — clauses, indemnity, liability — goes to ../contracts/SKILL.md; OCR, field extraction, or PDF splitting with no signing involved is ../document-processing/SKILL.md.
Pick the tier deliberately, before you write code: it decides which provider features you enable (ID Verification, SMS/access code, qualified signature), and getting it wrong leaves a signature that is hard to defend in court.
US law (ESIGN Act + UETA) has no tiers — e-signatures equal wet ink. The EU (eIDAS, and eIDAS 2.0 / Reg (EU) 2024/1183 in force since May 2024) defines three. A typed name (SES) is binding for most B2B in the US and EU, but a high-stakes EU document may need AES or QES. Map the document's stakes to a tier, then to a provider feature.
| Tier | What it is | When you need it | Provider feature to enable |
|---|---|---|---|
| SES (Simple) | Typed or drawn signature, basic intent + audit trail | Most B2B: offers, NDAs, quotes, US contracts generally | Default flow — just capture the signature + keep the audit trail |
| AES (Advanced) | Uniquely linked to signer, identity-verified, tamper-evident | Higher-value EU contracts, regulated sectors | ID Verification, SMS/access-code auth, signer authentication step |
| QES (Qualified) | EU handwritten-equivalent EU-wide; qualified cert via a QTSP | Where law mandates it (some real-estate, gov, regulated finance) | Qualified signature add-on through a Qualified Trust Service Provider |
If the document is genuinely high-stakes or you are unsure whether a tier is legally mandated, escalate to a lawyer and to ../contracts/SKILL.md — you do not give legal advice. Detail and the court-admissibility checklist live in references/legal-tiers.md.
Either is fine. Pick one and stay on it so you keep one consistent audit trail.
| DocuSign eSignature | Dropbox Sign (ex-HelloSign) | |
|---|---|---|
| Auth | OAuth 2.0 JWT Grant (RSA keypair, impersonation, one-time consent) | API key (header bearer) |
| Core call | create Envelope | signature_request/send |
| Node SDK | docusign-esign (9.0.0) | @dropbox/sign (1.11.0) — replaces deprecated hellosign-sdk |
| Embedded | clientUserId on recipient + recipient view URL | signature_request/create_embedded |
| Pricing posture | seat/envelope, enterprise-leaning | API: Essentials ~$75/mo (50+ requests, embedded signing included), Standard ~$250/mo annual (adds bulk send + higher volume), free test_mode |
| EU / QES | mature QES + ID Verification | SES/AES focus; check current QES support |
Never commit keys. Read everything from env; the RSA private key lives in a secret store or a file path, never inline in source.
Point at the sandbox before prod, always — a live send is billable and emails a real human. DocuSign demo env is https://demo.docusign.net; Dropbox Sign uses test_mode: 1. Only non-test sends count against quota and reach signers.
| Env var | Provider | Holds |
|---|---|---|
DOCUSIGN_INTEGRATION_KEY | DocuSign | client/integration key (GUID) |
DOCUSIGN_USER_ID | DocuSign | GUID of the user being impersonated |
DOCUSIGN_ACCOUNT_ID | DocuSign | API account ID |
DOCUSIGN_PRIVATE_KEY | DocuSign | RSA private key (PEM) — from secret store |
DOCUSIGN_BASE_PATH | DocuSign | https://demo.docusign.net/restapi in sandbox |
DROPBOX_SIGN_API_KEY | Dropbox Sign | API key |
DocuSign JWT Grant — five steps (full walk-through in references/docusign.md):
.../oauth/auth?response_type=code&scope=signature%20impersonation&client_id=...&redirect_uri=...).scope: signature impersonation), signed with the RSA private key./oauth/userinfo to discover the account's correct base path — do not hardcode the prod host while testing.Dropbox Sign needs only the API key as a bearer credential — see references/dropbox-sign.md.
# Bad: key in source, prod host while testing
const apiKey = "hs_live_abc123"; # committed secret
const base = "https://www.docusign.net"; # prod during a test
# Good: from env, sandbox first
export DROPBOX_SIGN_API_KEY="$(op read op://vault/dropbox-sign/key)"
export DOCUSIGN_BASE_PATH="https://demo.docusign.net/restapi"The core object is an Envelope. status: "sent" sends immediately; status: "created" saves a draft. Anchor strings let you place tabs by text in the PDF instead of fixed coordinates.
import docusign from "docusign-esign";
const env = {
emailSubject: "Please sign: Offer letter",
documents: [{
documentBase64: pdfBuffer.toString("base64"),
name: "Offer.pdf", fileExtension: "pdf", documentId: "1",
}],
recipients: {
signers: [{
email: signer.email, name: signer.name,
recipientId: "1", routingOrder: "1",
tabs: { signHereTabs: [{ anchorString: "/sig1/", anchorYOffset: "-10" }] },
}],
},
status: "sent", // "created" for a draft you send later
};
const api = new docusign.EnvelopesApi(apiClient); // apiClient configured with JWT token + base path
const result = await api.createEnvelope(accountId, { envelopeDefinition: env });
// store result.envelopeId — your handle for status, webhook correlation, and retrievalFor templates, send with templateId + templateRoles (prefilled tabs) instead of raw documents. Envelope/tabs anatomy and template send are in references/docusign.md.
The core call is signature_request/send (or signature_request/send_with_template). Keep testMode: true until you intend to spend a real request.
import * as DropboxSign from "@dropbox/sign";
const api = new DropboxSign.SignatureRequestApi();
api.username = process.env.DROPBOX_SIGN_API_KEY; // API key as username
const res = await api.signatureRequestSend({
title: "Offer letter",
subject: "Please sign",
signers: [{ emailAddress: signer.email, name: signer.name, order: 0 }],
files: [pdfBuffer], // or fileUrls
testMode: true, // flip to false ONLY when going live
});
// store res.body.signatureRequest.signatureRequestIdsend_with_template takes templateIds + signers mapped to template roles. Details and embedded creation are in references/dropbox-sign.md.
clientUserId on the recipient, then you request a recipient view URL and iframe/redirect to it. Dropbox Sign uses signature_request/create_embedded + the embedded sign URL. Embedded signing is included from the Dropbox Sign Essentials API plan up (it is not a Standard-only feature) — but it still requires a paid API plan, not test_mode alone.A send is not done when status is sent — it is done when the signer completes and you have pulled the signed document AND its evidence (DocuSign Certificate of Completion, Dropbox Sign audit-trail PDF), retrieved and stored. Fire-and-forget is the most common bug here.
Verify the signature before you trust anything in the payload. The body is attacker-controllable until you have verified it.
X-DocuSign-Signature-1 header against the raw request body using your Connect HMAC key.event_hash = HMAC-SHA256 of event_time + event_type, keyed by your API key.import crypto from "node:crypto";
// Dropbox Sign: verify event_hash before processing
function verifyDropboxSign(event, apiKey) {
const expected = crypto
.createHmac("sha256", apiKey)
.update(event.event.event_time + event.event.event_type)
.digest("hex");
return crypto.timingSafeEqual(
Buffer.from(expected), Buffer.from(event.event.event_hash));
}
// On a verified completion event: retrieve BOTH artifacts, idempotently
async function onCompleted(requestId) {
if (await alreadyHandled(requestId)) return; // idempotency guard
const signedPdf = await api.signatureRequestFiles(requestId, "pdf");
const auditTrail = await api.signatureRequestFiles(requestId, "pdf", { fileType: "audit" });
await store(requestId, signedPdf, auditTrail); // store IDs + bytes, never log bytes
await markHandled(requestId);
}For DocuSign, on the Completed envelope event call EnvelopesApi.getDocument for the signed PDF and for certificate to get the Certificate of Completion. HMAC verification code and Connect setup are in references/docusign.md.
| Anti-pattern | Why it is wrong | Do instead |
|---|---|---|
| Processing a webhook payload without verifying the signature | Anyone can POST a fake completed event | Verify HMAC (X-DocuSign-Signature-1 / event_hash) on the raw body first |
Trusting status from the request body you sent | Status lives with the provider, not your hope | Read status from the verified webhook or a status fetch |
| Sending from prod while still testing | Bills you and emails real people with test docs | DocuSign demo.docusign.net; Dropbox Sign testMode: true |
| Logging full document/envelope bytes or signer PII | Leaks the very PII the signature protects | Log provider IDs only; store bytes in a secret-aware store |
| Storing the signed PDF but not the audit trail | SES is hard to defend in court without who/what/when/where | Always pull the Certificate of Completion / audit-trail PDF too |
| Reusing one envelope/request to "retry" a send | Duplicates, double-bills, corrupts status | New request per send; use an idempotency guard on completion |
| Hardcoding the API key / RSA private key in source | Secret leak on first push | Env vars + secret store; key file path, never inline |
| Skipping the legal-tier decision | Ship a signature that is not legally adequate | Pick SES/AES/QES first; escalate high-stakes to a lawyer + ../contracts/SKILL.md |
Run scripts/verify.sh <path-to-integration> against the code you produced. It greps the artifact (no live API call) for: webhook signature verification present and not a TODO, no hardcoded API key or BEGIN PRIVATE KEY, a sandbox/test_mode guard, and a completion path that retrieves the signed PDF + audit trail. It is read-only and exits 0 on a clean/empty target.
For data-protection touchpoints (consent, retention of signed docs + PII), flag them and route the policy writing to ../gdpr-privacy/SKILL.md. For non-signing inbound webhook infrastructure, see ../webhooks/SKILL.md.
© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts, references) in skills/e-signature of ericrisco/rsc-harness.
Open the folder on GitHubat commit 1f8d9bb
E Signature next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| E Signature this skillericrisco/rsc-harness | 180 | — | ~3k | Automated safety check: Pass | MIT | |
| Build With SimplepdfSimplePDF/simplepdf-embed | 407 | — | ~7k | Automated safety check: Pass | MIT | |
| Google Apps Scriptjezweb/claude-skills | 1.1k | — | ~4.7k | Automated safety check: Pass | MIT | |
| Investigate Dropbox Sync Issueblotcms/blot | 2k | — | ~4.7k | Automated safety check: Pass | AGPL-3.0 | |
| Fullenrich Network ActivationOthmane-Khadri/YALC-the-GTM-operating-system | 318 | — | ~1.1k | Automated safety check: Warn | MIT | |
| Bio Reporting Rmarkdown ReportsGPTomics/bioSkills | 1.2k | 1 repos | ~2.1k | Automated safety check: Pass | MIT |
SimplePDF/simplepdf-embed
Integrate SimplePDF into a web application for PDF viewing, editing, filling, signing, programmatic control, AI-agent interaction, human-in-the-loop form prefilling, submissions, webhooks, or…
jezweb/claude-skills
Build Google Apps Script automation for Sheets and Workspace.
blotcms/blot
Investigate a "Dropbox sync issue" alert email from Blot's hourly Dropbox sync validation (each flagged blog lists unsynced changes, Fix() repairs, errors and/or a stuck folder lock; the changes…
Othmane-Khadri/YALC-the-GTM-operating-system
A skill your agent uses when the user says "activate co-founder network with FullEnrich", "enrich LinkedIn connections export", "qualify my LinkedIn connections CSV", "turn Connections.csv into a…
GPTomics/bioSkills
Creates reproducible R Markdown analysis reports (HTML, PDF, Word) with knitr, covering the render pipeline, the interactive-vs-knit session trap, cache invalidation, bookdown cross-references…
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when building Jinja templates in Frappe: Print Formats, Email Templates, Notification templates, Portal Pages, and custom Jinja methods.
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Works with
Categories
A skill your agent uses when wiring an e-signature flow with DocuSign or Dropbox Sign — picking the SES/AES/QES legal tier, sending a PDF or template for signature, embedded signing, verifying…. E Signature is an agent skill from ericrisco/rsc-harness. Use when wiring an e-signature flow with DocuSign or Dropbox Sign — picking the SES/AES/QES legal tier, sending a PDF or template for signature, embedded signing, verifying signing webhooks, retrieving the signed PDF plus audit trail.
E Signature fits situations like: wiring an e-signature flow with DocuSign; dropbox Sign — picking the SES/AES/QES legal tier; template for signature; embedded signing.
Run `npx skills add ericrisco/rsc-harness --skill e-signature -a claude-code`. Or copy the skill folder (skills/e-signature in ericrisco/rsc-harness) into .claude/skills/e-signature in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill e-signature -a codex`. Or copy the skill folder (skills/e-signature in ericrisco/rsc-harness) into .agents/skills/e-signature in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill e-signature -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/e-signature, .gemini/skills/e-signature, .github/skills/e-signature and .opencode/skills/e-signature in your project.
Going by SKILL.md and its folder, E Signature needs a shell for the scripts in its folder and credentials named DROPBOX_SIGN_API_KEY, DOCUSIGN_INTEGRATION_KEY and DOCUSIGN_PRIVATE_KEY. Our summary lists: A Bash shell; A credential in DOCUSIGN_INTEGRATION_KEY; A credential in DOCUSIGN_PRIVATE_KEY.
SKILL.md names 2 domains. In commands or code: demo.docusign.net and docusign.net; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
E Signature is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with E Signature: Build With Simplepdf (SimplePDF/simplepdf-embed, 407 stars), Google Apps Script (jezweb/claude-skills, 1.1k stars), Investigate Dropbox Sync Issue (blotcms/blot, 2k stars) and Fullenrich Network Activation (Othmane-Khadri/YALC-the-GTM-operating-system, 318 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 180 GitHub stars. The repository holds 233 skills in this directory. The repository was last updated on October 9, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.