Agent skill

Email

by magnus919 in magnus919/agent-skills

Send and diagnose transactional email through Twilio SendGrid from a terminal or agent: send messages, check deliverability (bounces and spam reports), and verify Signed Event Webhook signatures…

MITAuto-check passedBackend & APIs

Install Email

skills CLI
$ npx skills add magnus919/agent-skills --skill email -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install magnus919/agent-skills email --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/email .claude/skills/email && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
email
GitHub stars
115
Token cost
~2.4k tokens
SKILL.md length
1,003 words
Files
7 (incl. scripts, references)
Skills in repo
131
Repo updated
First seen
Licence
MIT

At a glance

Send and diagnose transactional email through Twilio SendGrid from a terminal or agent: send messages, check deliverability (bounces and spam reports), and verify Signed Event Webhook signatures…

  • Works in 6 steps: Read-only discovery before any mutation.… → Confirm the target, scope, and rollback… → Respect bounded reads. Suppression… → …
  • An agent needs to send a transactional email
  • SKILL.md covers Operating contract, The email-cli script, Operating loop and Sending transactional email, plus 7 more sections
  • Runs Python scripts from its folder

What it does

Email is an agent skill from magnus919/agent-skills. Send and diagnose transactional email through Twilio SendGrid from a terminal or agent: send messages, check deliverability (bounces and spam reports), and verify Signed Event Webhook signatures (ECDSA P-256) — with a bundled email-cli script that is read-only by default and gates every send behind a --dry-run/--yes confirmation. Use when an agent needs to send a transactional email, triage bounces or spam complaints, or confirm an inbound SendGrid webhook is authentic. Do not use for marketing or bulk email…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `README.md`, `evals/evals.json` and `references/00-source-index.md`). Compatibility notes: The bundled email-cli script runs on Python 3.9+ with only the standard library, including the self-contained ECDSA P-256 webhook verifier. --help…

It sits in Backend & APIs, covering Transactional email and Webhooks. It works with SendGrid. The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.

When your agent uses it

  • An agent needs to send a transactional email
  • Spam complaints
  • Confirm an inbound SendGrid webhook is authentic
  • Bulk email campaigns (that is SendGrid Marketing Campaigns)

Example prompts

  • “/email”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): The bundled email-cli script runs on Python 3.9+ with only the standard library, including the self-contained ECDSA P-256 webhook verifier. --help, deliverability checks, and signature verification need no network; sending requires a SendGrid API key with mail.send access and network access to api.sendgrid.com.

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Read-only discovery before any mutation. Check deliverability signals (bounces, spam reports) freely. The bundled email-cli script makes…
  2. Confirm the target, scope, and rollback path before acting. Sending email puts words in recipients' inboxes in your organization's name…
  3. Respect bounded reads. Suppression listings cap results with --limit; never page past what the task needs.
  4. Verify webhooks before trusting them. SendGrid's Signed Event Webhook signs every request; verify the ECDSA signature and timestamp before…
  5. Keep evidence bounded. Quote short message previews and email addresses; never paste API keys, full message bodies, or suppression lists…
  6. Never send to unverified addresses or real users without a directive. Deliverability triage reads are safe; the send path is always gated.

What it can do on your machine

Read from SKILL.md and the folder at commit 22b4723. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    The bundled email-cli script runs on Python 3.9+ with only the standard library, including the self-contained ECDSA P-256 webhook verifier. --help, deliverability checks, and signature verification need no network; sending requires a SendGrid API key with mail.send access and network access to api.sendgrid.com.

    From compatibility in the SKILL.md frontmatter.

Context cost

Email loads about 2.4k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 164 tokens; SKILL.md has 1,003 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~164
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from magnus919/agent-skills at commit 22b4723, republished under its MIT licence (© magnus919). 1,003 words, ~2,378 tokens.

Download SKILL.mdSave it as .claude/skills/email/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
email
description
Send and diagnose transactional email through Twilio SendGrid from a terminal or agent: send messages, check deliverability (bounces and spam reports), and verify Signed Event Webhook signatures (ECDSA P-256) — with a bundled email-cli script that is read-only by default and gates every send behind a --dry-run/--yes confirmation. Use when an agent needs to send a transactional email, triage bounces or spam complaints, or confirm an inbound SendGrid webhook is authentic. Do not use for marketing or bulk email campaigns (that is SendGrid Marketing Campaigns), building email template systems, or other email providers (that is their own tooling).
compatibility
The bundled email-cli script runs on Python 3.9+ with only the standard library, including the self-contained ECDSA P-256 webhook verifier. --help, deliverability checks, and signature verification need no network; sending requires a SendGrid API key with mail.send access and network access to api.sendgrid.com.
license
MIT
metadata.source
https://www.twilio.com/docs/sendgrid
metadata.source_index
references/00-source-index.md
metadata.research_checked
2026-08-03

Transactional Email Operations (SendGrid)

Use this skill to send transactional email through Twilio SendGrid and to diagnose delivery: bounces, spam complaints, and the Signed Event Webhook. This is a tool skill for one vendor (SendGrid). Marketing campaigns, template builders, and other providers are out of scope; this skill owns the operational loop for application-triggered email: send it, check it landed, and verify the events claiming so are authentic.

Operating contract

  1. Read-only discovery before any mutation. Check deliverability signals (bounces, spam reports) freely. The bundled email-cli script makes reads without writing anything.
  2. Confirm the target, scope, and rollback path before acting. Sending email puts words in recipients' inboxes in your organization's name: it requires an explicit human directive naming the recipients, sender, and content, plus --dry-run preview and --yes confirmation through email-cli. There is no reliable "un-send" for delivered mail.
  3. Respect bounded reads. Suppression listings cap results with --limit; never page past what the task needs.
  4. Verify webhooks before trusting them. SendGrid's Signed Event Webhook signs every request; verify the ECDSA signature and timestamp before acting on event data. Unverified webhook endpoints accept forged delivery/bounce events.
  5. Keep evidence bounded. Quote short message previews and email addresses; never paste API keys, full message bodies, or suppression lists into chat.
  6. Never send to unverified addresses or real users without a directive. Deliverability triage reads are safe; the send path is always gated.

The email-cli script

scripts/email-cli is an agent-first, stdlib-only CLI over the SendGrid v3 API, including a self-contained ECDSA P-256 signature verifier with no third-party crypto dependency.

bash
email/scripts/email-cli --help                              # no key or network needed
email/scripts/email-cli --json --limit 20 deliverability bounces
email/scripts/email-cli --json --limit 20 deliverability spam-reports
email/scripts/email-cli send --to user@example.com --from no-reply@example.com \
  --subject "Password reset" --body "..." --dry-run          # preview only
email/scripts/email-cli send --to user@example.com --from no-reply@example.com \
  --subject "Password reset" --body "..." --yes              # confirmed send
email/scripts/email-cli webhook verify --body-file body.json \
  --signature "MEUC..." --timestamp 1712345678 --public-key-file public-key.pem

Exit codes: 0 success, 1 API error or failed verification, 2 usage error. Sends are guarded: without --dry-run or --yes the script refuses with exit 1 and never calls the API. Reads are bounded by --limit (default 20, max 100).

Operating loop

  1. Scope the delivery question: is this a send (mutation) or a deliverability investigation (read)? Who is the sender, who receives, what is the content?
  2. Read with bounds: deliverability bounces and deliverability spam-reports to see who failed to receive and why.
  3. Triage the signal: map the evidence to the cause (hard bounce → bad or typo'd address; spam complaint → content or frequency problem; suppression list → prior bounce). Check SendGrid's event webhook payloads for delivery/bounce events — after verifying the signature.
  4. Act with confirmation: only a human directive to send, previewed with --dry-run and confirmed with --yes.
  5. Verify: confirm the send response (x-message-id), then later confirm delivery via webhook/API evidence rather than assuming.

Sending transactional email

  • Compose the message: verified sender (from), one or more to recipients, subject, plain-text body, and optionally an html body. SendGrid requires the from-address to be a verified sender identity on your account.
  • Preview before sending: --dry-run prints the exact from/to/subject/body preview and never calls the API. --yes confirms and posts to POST /v3/mail/send, which returns 202 Accepted with the x-message-id header.
  • Do not send secrets or tokens by email. Email is a leak channel; a password-reset link is fine, a raw credential is not.
  • SendGrid returns 202 (accepted) — acceptance is not delivery. Confirm delivery from the event webhook or the activity feed before claiming success.

Deliverability checks

  • Bounces (GET /suppression/bounces): recipients whose mail bounced, with reason and status. Hard bounces (5.x.x permanent) indicate invalid addresses; repeated bounces hurt sender reputation.
  • Spam reports (GET /suppression/spam_reports): recipients who marked mail as spam. Frequent complaints indicate a content or targeting problem.
  • Deliverability triage is read-only: diagnose from the suppression lists and webhook events, then change the next send (a mutation) only with confirmation.
Show full SKILL.md (413 more words)Show less

Webhook signature verification

SendGrid's Signed Event Webhook signs each request with an ECDSA key pair. To verify:

  1. Take the exact raw request body bytes — any re-encoding breaks the signature.
  2. Check X-Twilio-Email-Event-Webhook-Timestamp is recent (replay protection; email-cli default window 300s, disable with --max-age 0).
  3. Compute SHA-256 over timestamp + raw body (bytes concatenated, no separator) and verify the ECDSA P-256 signature (X-Twilio-Email-Event-Webhook-Signature, base64-decoded ASN.1 DER) against the webhook public key.
  4. Reject with 401 if the timestamp is stale or the signature does not verify.

email-cli webhook verify --body-file body.json --signature <header> --timestamp <header> --public-key-file public-key.pem runs exactly this check with a stdlib-only P-256 implementation. The public key is shown in the Event Webhook settings when Signed Webhook is enabled; store it as a file, never in code.

Reference routing

Load whenReference
Sources, refresh procedurereferences/00-source-index.md
API surface, webhook verification details, deliverability semanticsreferences/01-sendgrid-operations.md

Included artifacts

  • scripts/email-cli: bounded, stdlib-only CLI (send, deliverability bounces/spam-reports, webhook verify with self-contained ECDSA P-256; --json; --limit; send gated by --dry-run/--yes).
  • tests/test_email_cli.py: 15 deterministic tests against a stub SendGrid API plus OpenSSL-generated ECDSA webhook vectors (independent cross-check of the verifier).
  • references/: dated source index + SendGrid operations reference.
  • evals/evals.json: six output-quality evaluation cases for agent runs.

Verification boundary

ClaimMinimum evidence
A message was acceptedemail-cli send --yes exits 0 and returns the x-message-id
A recipient bouncedemail-cli deliverability bounces --json lists the address with reason and status
A webhook is authenticemail-cli webhook verify exits 0 with verified: true for the exact body/signature/timestamp
Delivery actually happenedDelivery webhook event (verified) or activity feed shows the message as delivered

Hard boundaries

  • Never send email without a human directive, --dry-run preview, and --yes confirmation — sent mail is durable, external, and in recipients' inboxes.
  • Never trust an inbound webhook without ECDSA signature and timestamp verification.
  • Never page reads past --limit; never dump full message bodies, API keys, or suppression lists into chat.
  • This skill covers SendGrid transactional email only. Marketing campaigns, template systems, and other providers are out of scope.

When not to use

  • Marketing or bulk email campaigns (SendGrid Marketing Campaigns, segmentation, blast sends) — that is a different product surface with its own tooling.
  • Other email providers (Postmark, SES, Mailgun, Resend) — each has its own API; this skill covers SendGrid.
  • Designing email deliverability strategy or domain reputation policy at org scale — that is operational policy work; this skill operates the SendGrid surface.
  • Building an email feature into an application (template rendering, transactional flows) — that is application development; see backend-engineering.

© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in email of magnus919/agent-skills.

  • SKILL.md
  • README.md
  • evals/evals.json
  • references/00-source-index.md
  • references/01-sendgrid-operations.md
  • scripts/email-cli
  • tests/test_email_cli.py

Open the folder on GitHubat commit 22b4723

Compare with similar skills

Email next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Email compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Email this skillmagnus919/agent-skills115—~2.4kAutomated safety check: PassMIT
Email Connectorericrisco/rsc-harness180—~3.1kAutomated safety check: PassMIT
Email Best Practicesviclafouch/meme-studio1107 repos~787Automated safety check: PassNone
Loops APIopeninary/openinary412—~1.1kAutomated safety check: PassAGPL-3.0
E2a Doctortokencanopy/e2a193—~994Automated safety check: PassApache-2.0
E2a Integratetokencanopy/e2a193—~840Automated safety check: PassApache-2.0

Similar skills

  • Email Connector

    ericrisco/rsc-harness

    A skill your agent uses when wiring server code to send transactional or bulk email via Resend, SendGrid, or Postmark: a provider-agnostic sendEmail() seam, idempotent retries, 100-cap batches with…

    180 GitHub stars~3.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Email Best Practices

    viclafouch/meme-studio

    A skill your agent uses when building email features, emails going to spam, high bounce rates, setting up SPF/DKIM/DMARC authentication, implementing email capture, ensuring compliance (CAN-SPAM…

    110 GitHub starsUsed in 7 repos~787 tokens
    Backend & APIsAuto-check passed
  • Loops API

    openinary/openinary

    A skill your agent uses whenever the user wants to integrate Loops from application code, backend services, webhook handlers, or server-side automation.

    412 GitHub stars~1.1k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • E2a Doctor

    tokencanopy/e2a

    A skill your agent uses when an existing e2a MCP connection, inbox, custom domain, protection policy, webhook, or message delivery is failing or unclear.

    193 GitHub stars~994 tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • E2a Integrate

    tokencanopy/e2a

    A skill your agent uses when adding e2a email capabilities to an application or codebase: outbound sending, inbound signed webhooks, REST polling, or SDK integration.

    193 GitHub stars~840 tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Email Service

    cohen-liel/hivemind

    Email sending patterns for transactional and marketing emails.

    110 GitHub stars~1.8k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed

More from magnus919/agent-skills

All 131 skills in this repo
  • Artifact Pyramids

    magnus919/agent-skills

    Organize durable agent research outputs as summaries, analysis, and evidence dossiers.

    115 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Ascii City Engine

    magnus919/agent-skills

    Build portable, first-person colored ASCII city engines and small GIS-derived city packs.

    115 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Color Management

    magnus919/agent-skills

    Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.

    115 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Data Scientist

    magnus919/agent-skills

    A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…

    115 GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Docker Compose

    magnus919/agent-skills

    Use Docker Compose to define, run, debug, and harden multi-container applications.

    115 GitHub stars~2k tokensUpdated today
    Auto-check: notes
  • Fpga Development

    magnus919/agent-skills

    Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.

    115 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Email

What does Email do?

Send and diagnose transactional email through Twilio SendGrid from a terminal or agent: send messages, check deliverability (bounces and spam reports), and verify Signed Event Webhook signatures…. Email is an agent skill from magnus919/agent-skills. Send and diagnose transactional email through Twilio SendGrid from a terminal or agent: send messages, check deliverability (bounces and spam reports), and verify Signed Event Webhook signatures (ECDSA P-256) — with a bundled email-cli script that is read-only by default and gates every send behind a --dry-run/--yes confirmation.

When should I use Email?

Email fits situations like: an agent needs to send a transactional email; spam complaints; confirm an inbound SendGrid webhook is authentic; bulk email campaigns (that is SendGrid Marketing Campaigns).

How do I install Email in Claude Code?

Run `npx skills add magnus919/agent-skills --skill email -a claude-code`. Or copy the skill folder (email in magnus919/agent-skills) into .claude/skills/email in your project. Claude Code loads it when a task matches its description.

How do I install Email in Codex?

Run `npx skills add magnus919/agent-skills --skill email -a codex`. Or copy the skill folder (email in magnus919/agent-skills) into .agents/skills/email in your project. Codex loads it when a task matches its description.

Can I use Email in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill email -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/email, .gemini/skills/email, .github/skills/email and .opencode/skills/email in your project.

What does Email need to run?

Going by SKILL.md and its folder, Email needs Python for the scripts in its folder. Our summary lists: Python 3. Compatibility (from SKILL.md): The bundled email-cli script runs on Python 3.9+ with only the standard library, including the self-contained ECDSA P-256 webhook verifier. --help, deliverability checks, and signature verification need no network; sending requires a SendGrid API key with mail.send access and network access to api.sendgrid.com..

Does Email access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Email safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Email use?

Email is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Email use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Email?

Skills that share tags, products or a category with Email: Email Connector (ericrisco/rsc-harness, 180 stars), Email Best Practices (viclafouch/meme-studio, 110 stars), Loops API (openinary/openinary, 412 stars) and E2a Doctor (tokencanopy/e2a, 193 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Email?

magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 115 GitHub stars. The repository holds 131 skills in this directory. The repository was last updated on October 10, 2026.

Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.