Agent skill

Email Evals

by tokencanopy in tokencanopy/e2a

Author and safely run deterministic email-agent evaluation suites with dedicated e2a test agents.

Apache-2.0Auto-check passedAI & LLM Engineering

Install Email Evals

skills CLI
$ npx skills add tokencanopy/e2a --skill email-evals -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tokencanopy/e2a email-evals --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tokencanopy/e2a.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/e2a/skills/email-evals .claude/skills/email-evals && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
email-evals
GitHub stars
192
Token cost
~2.1k tokens
SKILL.md length
953 words
Files
103
Skills in repo
8
Repo updated
First seen
Licence
Apache-2.0

At a glance

Author and safely run deterministic email-agent evaluation suites with dedicated e2a test agents.

  • Works in 12 steps: <!-- email-evals:field=use-case --> use… → <!--… → <!--… → …
  • A user wants to define synthetic email cases
  • SKILL.md covers Gather the suite one answer at…, Contain the evaluation before…, Scaffold, edit, and validate and Request approval immediately…, plus 2 more sections
  • Runs JavaScript and Shell scripts from its folder; reaches api.e2a.dev; needs E2A_EVAL_API_KEY

What it does

Email Evals is an agent skill from tokencanopy/e2a. Author and safely run deterministic email-agent evaluation suites with dedicated e2a test agents. Use when a user wants to define synthetic email cases, validate a suite, inspect its dry-run plan, run it after approval, or regrade changed assertions.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 104 other files (for example `email-evals.sh`, `runtime/THIRD_PARTY_NOTICES.md` and `runtime/package-lock.json`).

It sits in AI & LLM Engineering, covering LLM evaluation, Agent evaluation and testing and Transactional email. The repository describes itself as: Open-source email API for applications and AI agents. Managed hosting at e2a.dev, or self-host with Docker. The licence is Apache-2.0.

When your agent uses it

  • A user wants to define synthetic email cases
  • Validate a suite
  • Inspect its dry-run plan
  • Run it after approval

Example prompts

  • “/email-evals”

Requirements

  • Node.js
  • A Bash shell
  • A credential in E2A_EVAL_API_KEY

Workflow steps

12 steps, taken from the first numbered list in SKILL.md.

  1. <!-- email-evals:field=use-case --> use case — Ask: “What is the synthetic use case?”
  2. <!-- email-evals:field=existing-target-runtime --> existing target runtime — Ask: “Does the existing target runtime already run?”
  3. <!-- email-evals:field=dedicated-actor-environment-name --> dedicated actor environment name — Ask: “What is the dedicated actor…
  4. <!-- email-evals:field=dedicated-target-environment-name --> dedicated target environment name — Ask: “What is the dedicated target…
  5. <!-- email-evals:field=expected-action --> expected action — Ask: “What is the expected action?”
  6. <!-- email-evals:field=exact-allowed-recipients --> exact allowed recipients — Ask: “Which exact allowed recipients are required?”
  7. <!-- email-evals:field=sender --> sender — Ask: “What is the sender?”
  8. <!-- email-evals:field=reply-to --> Reply-To — Ask: “What is the Reply-To expectation?”
  9. <!-- email-evals:field=thread --> thread — Ask: “What is the thread expectation?”
  10. <!-- email-evals:field=subject --> subject — Ask: “What is the subject expectation?”
  11. <!-- email-evals:field=required-facts --> required facts — Ask: “What required facts apply?”
  12. <!-- email-evals:field=forbidden-patterns --> forbidden patterns — Ask: “What forbidden patterns apply?”

What it can do on your machine

Read from SKILL.md and the folder at commit 776fe2c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript and Shell, from the files we listed), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.e2a.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • E2A_EVAL_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Email Evals loads about 2.1k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 953 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tokencanopy/e2a at commit 776fe2c, republished under its Apache-2.0 licence (© tokencanopy). 953 words, ~2,095 tokens.

Download SKILL.mdSave it as .claude/skills/email-evals/SKILL.md (or your agent's skills folder). This skill also uses 102 other files; get the full folder from GitHub.
name
email-evals
description
Author and safely run deterministic email-agent evaluation suites with dedicated e2a test agents. Use when a user wants to define synthetic email cases, validate a suite, inspect its dry-run plan, run it after approval, or regrade changed assertions.

Email evals

Gather the suite one answer at a time

Ask one logical question at a time; do not dump a questionnaire. Ask exactly one prompt, wait for the answer, then advance. Conditionally omit a later prompt only when an earlier answer proves its field irrelevant; never bundle prompts.

<!-- email-evals:authoring-prompts:start -->
  1. <!-- email-evals:field=use-case --> **use case** — Ask: “What is the synthetic use case?”
  2. <!-- email-evals:field=existing-target-runtime --> **existing target runtime** — Ask: “Does the existing target runtime already run?”
  3. <!-- email-evals:field=dedicated-actor-environment-name --> **dedicated actor environment name** — Ask: “What is the dedicated actor environment name?”
  4. <!-- email-evals:field=dedicated-target-environment-name --> **dedicated target environment name** — Ask: “What is the dedicated target environment name?”
  5. <!-- email-evals:field=expected-action --> **expected action** — Ask: “What is the expected action?”
  6. <!-- email-evals:field=exact-allowed-recipients --> **exact allowed recipients** — Ask: “Which exact allowed recipients are required?”
  7. <!-- email-evals:field=sender --> **sender** — Ask: “What is the sender?”
  8. <!-- email-evals:field=reply-to --> **Reply-To** — Ask: “What is the Reply-To expectation?”
  9. <!-- email-evals:field=thread --> **thread** — Ask: “What is the thread expectation?”
  10. <!-- email-evals:field=subject --> **subject** — Ask: “What is the subject expectation?”
  11. <!-- email-evals:field=required-facts --> **required facts** — Ask: “What required facts apply?”
  12. <!-- email-evals:field=forbidden-patterns --> **forbidden patterns** — Ask: “What forbidden patterns apply?”
  13. <!-- email-evals:field=attachments --> **attachments** — Ask: “What attachments are expected?”
  14. <!-- email-evals:field=timeout --> **timeout** — Ask: “What timeout applies?”
  15. <!-- email-evals:field=lifecycle --> **lifecycle** — Ask: “What lifecycle outcome is required?”
<!-- email-evals:authoring-prompts:end -->

This skill does not build or start the target agent runtime.

Refuse real customer messages, identifiers, customer domains, or production-derived fixtures. Immediately propose a synthetic replacement, such as a fictional order identifier and a .test mailbox. Keep every case and attachment synthetic.

Do not scaffold until these answers are sufficient to make deterministic assertions.

Contain the evaluation before setup

Never change e2a protection. Tell the user to configure containment separately, in the same dedicated account for e2a, with an account-scoped API key:

  • actor: allowlist/block [target]
  • target: allowlist/block [actor, probes...]

Use dedicated actor and target agents only. Do not infer, broaden, or repair protection settings; surface protection failures during validation instead.

Scaffold, edit, and validate

After gathering sufficient answers, scaffold the suite:

Resolve the absolute directory containing this loaded SKILL.md resource. For the tool call, set EMAIL_EVALS_LAUNCHER to the absolute path formed by joining that resource directory with email-evals.sh. This is an agent-local value, not a persisted environment variable. Do not derive it from the user's current directory or a client-specific plugin-root variable.

sh
"$EMAIL_EVALS_LAUNCHER" scaffold --root <suite-root> --name <suite-name> --target-env <target-env> --actor-env <actor-env>

Edit the generated suite.yaml and case YAML files to reflect the answers. The credential name is fixed outside suite authority: export only E2A_EVAL_API_KEY. YAML interpolation is limited to the documented actor, target, and probe mailbox fields; never interpolate names, actions, timing, subjects, bodies, patterns, or attachment metadata.

Then verify the checked-in, single-file plugin runtime bundle and validate the suite. Setup performs no package installation and never copies or executes JavaScript or dependencies beneath the suite root:

Resolve the absolute directory containing this loaded SKILL.md resource. For the tool call, set EMAIL_EVALS_LAUNCHER to the absolute path formed by joining that resource directory with email-evals.sh. This is an agent-local value, not a persisted environment variable. Do not derive it from the user's current directory or a client-specific plugin-root variable.

sh
"$EMAIL_EVALS_LAUNCHER" setup --root <suite-root>
"$EMAIL_EVALS_LAUNCHER" validate --suite <suite-root>/suite.yaml

Show the complete alias-only dry-run plan, its approvalDigest, and any protection failures. Validation is the preflight gate; do not run a suite while it reports a protection or capability failure. Treat the digest as an opaque value; it binds the resolved identities, origin, containment posture, stimuli, assertions, recipients, and execution limits without revealing them.

The public https://api.e2a.dev origin is the default. If the suite names a custom/local origin, the operator must independently authorize the exact origin on every command with --trusted-origin <origin>; cleartext origins are restricted to loopback. Never infer this flag from suite content.

Show full SKILL.md (374 more words)Show less

Request approval immediately before sending

Ask for explicit user approval immediately before run, because it sends real email between the dedicated agents. Do not treat earlier authoring answers as approval.

Only after that approval, run:

Resolve the absolute directory containing this loaded SKILL.md resource. For the tool call, set EMAIL_EVALS_LAUNCHER to the absolute path formed by joining that resource directory with email-evals.sh. This is an agent-local value, not a persisted environment variable. Do not derive it from the user's current directory or a client-specific plugin-root variable.

sh
"$EMAIL_EVALS_LAUNCHER" run --suite <suite-root>/suite.yaml --approval-digest <approvalDigest-from-validate>

If the suite, resolved mailbox identities, custom origin, protection posture, or plan changed since validation, run fails closed. Validate again, show the new complete plan, and request fresh approval; never substitute or guess a digest.

Inspect and iterate

Read the generated report.md. Summarize deterministic failures without hiding errors, then propose the smallest case/agent change that addresses each failure.

When only assertions changed, use regrade instead of run; regrade performs no sends:

Resolve the absolute directory containing this loaded SKILL.md resource. For the tool call, set EMAIL_EVALS_LAUNCHER to the absolute path formed by joining that resource directory with email-evals.sh. This is an agent-local value, not a persisted environment variable. Do not derive it from the user's current directory or a client-specific plugin-root variable.

sh
"$EMAIL_EVALS_LAUNCHER" regrade --suite <suite-root>/suite.yaml --run <run-dir>

Regrade accepts a changed full-suite digest only when the execution digest is unchanged. It always uses the current validated assertions and rejects changes to sending, correlation, timing, containment, actor, target, or origin inputs. The output root also contains the private mode-0600 .email-evals-artifact-auth-key, which authenticates redaction-loss metadata independently of the rotatable API key. Keep that hidden file with its run directories; never publish it or place it inside a suite. Every ordinary case record carries authenticated redaction state, including an explicit empty declaration when no text was erased. Regrade fails closed if this authentication root or a case's authenticated redaction state is missing, replaced, or altered. If body evidence required configured-pattern redaction, the forbidden-pattern set must remain identical (reordering is allowed); changing that set fails closed because arbitrary new regexes cannot be evaluated against erased text.

V0 limits

Keep claims within the launch slice: no semantic judge, no deep HTML equivalence, no scheduled-send proof, and no full review/bounce/complaint matrix. Do not promise simulator, model, or data-generator features.

© tokencanopy, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 102 other files in plugins/e2a/skills/email-evals of tokencanopy/e2a.

  • SKILL.md
  • email-evals.sh
  • launcher.mjs
  • runtime/THIRD_PARTY_NOTICES.md
  • runtime/cli.mjs
  • runtime/email-evals-runtime.bundle.mjs
  • runtime/lib/cli-arguments.mjs
  • runtime/lib/contract.mjs
  • runtime/lib/e2a-adapter.mjs
  • runtime/lib/errors.mjs
  • runtime/lib/grade-content.mjs
  • runtime/lib/grade-core.mjs
  • runtime/lib/mime.mjs
  • runtime/lib/normalize.mjs
  • runtime/lib/report.mjs
  • runtime/lib/result-contract.mjs
  • runtime/lib/runner.mjs
  • runtime/lib/safe-pattern.mjs
  • runtime/package-lock.json
  • … and 84 more

Open the folder on GitHubat commit 776fe2c

Compare with similar skills

Email Evals next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Email Evals compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Email Evals this skilltokencanopy/e2a192—~2.1kAutomated safety check: PassApache-2.0
Benchflowbenchflow-ai/benchflow353—~1.9kAutomated safety check: NotesApache-2.0
Agent Eval Engineeringlangchain-ai/langchain-skills1.3k—~4kAutomated safety check: PassMIT
Autocontextgreyhaven-ai/autocontext1.3k—~892Automated safety check: PassApache-2.0
GAIA Agent Benchmarkingamd/gaia1.6k—~1.8kAutomated safety check: PassMIT
Bkit Evalsww-w-ai/bkit-claude-code600—~1kAutomated safety check: NotesApache-2.0

Similar skills

  • Benchflow

    benchflow-ai/benchflow

    Run agent benchmarks, create tasks, analyze results, and manage agents using BenchFlow.

    353 GitHub stars~1.9k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check: notes
  • Agent Eval Engineering

    langchain-ai/langchain-skills

    Official

    Builds agent evaluations in stages: inspect the repository and traces, agree a Task Spec with you, then build, audit and run a Harbor task with an independent verifier.

    1.3k GitHub stars~4k tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed
  • Autocontext

    greyhaven-ai/autocontext

    Runs LLM-based rubric judging on agent output and loops revise-and-rejudge rounds until a quality threshold is met.

    1.3k GitHub stars~892 tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Benchmarks AMD's GAIA agent against Claude Code and across models on quality, honesty, steps, tokens, time and real cost, using gaia eval tasks.

    1.6k GitHub stars~1.8k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Bkit Evals

    ww-w-ai/bkit-claude-code

    Run skill evals via evals/runner.js — wrapper validates skill names, captures stdout/stderr, persists JSON results.

    600 GitHub stars~1k tokensUpdated 10 days ago
    AI & LLM EngineeringAuto-check: notes
  • Windmill AI Evals

    windmill-labs/windmill

    Writes and runs black-box benchmark cases for Windmill's flow, app, script, CLI and global AI generation modes, including before-and-after comparisons.

    18k GitHub stars~969 tokensUpdated today
    AI & LLM EngineeringAuto-check: notes

More from tokencanopy/e2a

All 8 skills in this repo
  • Autopilot

    tokencanopy/e2a

    Conversationally configure and operate a policy-first, always-on local e2a email agent.

    192 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • E2a

    tokencanopy/e2a

    A skill your agent uses when operating an already-connected e2a inbox over MCP: reading, composing, sending, replying, forwarding, handling attachments, managing contacts/outreach, scheduling mail…

    192 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed
  • Tether

    tokencanopy/e2a

    Beta — Stay in the loop over email during a long-running coding session.

    192 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed
  • Agentify

    tokencanopy/e2a

    Beta — Deploy the autonomous-repo feedback loop into a GitHub repo.

    192 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • E2a Doctor

    tokencanopy/e2a

    A skill your agent uses when an existing e2a MCP connection, inbox, custom domain, protection policy, webhook, or message delivery is failing or unclear.

    192 GitHub stars~994 tokensUpdated yesterday
    Auto-check passed
  • E2a Integrate

    tokencanopy/e2a

    A skill your agent uses when adding e2a email capabilities to an application or codebase: outbound sending, inbound signed webhooks, REST polling, or SDK integration.

    192 GitHub stars~840 tokensUpdated yesterday
    Auto-check passed

Questions about Email Evals

What does Email Evals do?

Author and safely run deterministic email-agent evaluation suites with dedicated e2a test agents. Email Evals is an agent skill from tokencanopy/e2a. Author and safely run deterministic email-agent evaluation suites with dedicated e2a test agents.

When should I use Email Evals?

Email Evals fits situations like: A user wants to define synthetic email cases; validate a suite; inspect its dry-run plan; run it after approval.

How do I install Email Evals in Claude Code?

Run `npx skills add tokencanopy/e2a --skill email-evals -a claude-code`. Or copy the skill folder (plugins/e2a/skills/email-evals in tokencanopy/e2a) into .claude/skills/email-evals in your project. Claude Code loads it when a task matches its description.

How do I install Email Evals in Codex?

Run `npx skills add tokencanopy/e2a --skill email-evals -a codex`. Or copy the skill folder (plugins/e2a/skills/email-evals in tokencanopy/e2a) into .agents/skills/email-evals in your project. Codex loads it when a task matches its description.

Can I use Email Evals in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tokencanopy/e2a --skill email-evals -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/email-evals, .gemini/skills/email-evals, .github/skills/email-evals and .opencode/skills/email-evals in your project.

What does Email Evals need to run?

Going by SKILL.md and its folder, Email Evals needs JavaScript and a shell for the scripts in its folder and credentials named E2A_EVAL_API_KEY. Our summary lists: Node.js; A Bash shell; A credential in E2A_EVAL_API_KEY.

Does Email Evals access the network?

SKILL.md names 1 domain. In commands or code: api.e2a.dev; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Email Evals safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Email Evals use?

Email Evals is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Email Evals use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Email Evals?

Skills that share tags, products or a category with Email Evals: Benchflow (benchflow-ai/benchflow, 353 stars), Agent Eval Engineering (langchain-ai/langchain-skills, 1.3k stars), Autocontext (greyhaven-ai/autocontext, 1.3k stars) and GAIA Agent Benchmarking (amd/gaia, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Email Evals?

tokencanopy (a GitHub organization) maintains it in tokencanopy/e2a, which has 192 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 6, 2026.

Source: tokencanopy/e2a on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.