Customerio Cost TuningSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: customerio-cost-tuning description: 'Optimize Customer.io costs and usage efficiency. Use when reducing profile count, cleaning inactive users, deduplicating events, or right-sizing your plan. Trigger: "customer.io cost", "reduce customer.io spend", "customer.io billing", "customer.io pricing", "customer.io cleanup". ' allowed-tools: Read, Write, Edit, Bash(npm:*), Bash(npx:*), Glob, Grep version: 1.14.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - customer-io - cost-optimization - billing compatibility: Designed for Claude Code --- # Customer.io Cost Tuning ## Prerequisites - An approved cost owner, billing/usage baseline, message/event retention policy, and delivery SLO. - Aggregate reporting that does not require exporting customer payloads or individual message content. ## Output - A measured cost optimization with owner, delivery/consent guardrails, and rollback threshold. - An aggregate usage receipt supporting the decision without exposing recipient data. ## Error Handling | Condition | Safe response | |---|---| | Spend rises unexpectedly | Verify configuration, rate, and authorized campaigns; pause unsafe scale changes and investigate aggregate signals. | | Optimization risks delivery or consent | Do not apply it until the service/data owner approves a safe test. | | Data is missing or misallocated | Repair attribution before making a budget decision. | ## Examples Compare aggregate event volume and message spend for a development/staging campaign, reduce unnecessary duplicate events through an idempotency fix, and observe the agreed window. Revert if delivery errors, latency, or consent checks regress; do not suppress customer messages solely to make a dashboard look cheaper. ## Overview Optimize Customer.io costs by managing profile count (the primary billing driver), suppressing/deleting inactive users, deduplicating events, reducing unnecessary API calls, and monitoring usage trends. ## How Customer.io Pricing Works Customer.io bills based on **profile count** (number of identified people in your workspace) and **email/SMS volume**. Key cost drivers: | Factor | Impact | Optimization Strategy | |--------|--------|----------------------| | Total profiles | Primary cost driver | Delete inactive profiles | | Email sends | Per-email cost above tier | Suppress unengaged users | | SMS sends | Per-SMS cost | Only send to opt-in users | | Overidentification | Creates unnecessary profiles | Don't identify users who'll never receive messages | | Event volume | Can increase processing costs | Deduplicate and sample | ## Instructions ### Step 1: Profile Audit ```typescript // scripts/cio-profile-audit.ts // Audit your Customer.io integration for cost optimization opportunities import { TrackClient, RegionUS } from "customerio-node"; const cio = new TrackClient( process.env.CUSTOMERIO_SITE_ID!, process.env.CUSTOMERIO_TRACK_API_KEY!, { region: RegionUS } ); // Check: Are you identifying users who'll never receive messages? const AUDIT_RULES = { // Users without email can't receive email campaigns noEmail: "Don't identify users without email unless using push/SMS", // Test users should be cleaned up testUsers: "Suppress and delete test-*, ci-*, dev-* prefixed users", // Anonymous users that never convert inflate profile count staleAnonymous: "Delete anonymous profiles older than 90 days without conversion", // Inactive users who haven't opened email in 6+ months unengaged: "Suppress users with no email opens in 180+ days", }; console.log("=== Customer.io Cost Audit Rules ===\n"); for (const [rule, action] of Object.entries(AUDIT_RULES)) { console.log(`${rule}: ${action}`); } console.log("\nRun these checks in Customer.io dashboard:"); console.log("1. People > Segments > Create 'Inactive 90 days' segment"); console.log("2. People > Segments > Create 'No email attribute' segment"); console.log("3. People > Filter by created_at < 90 days ago AND email_opened = 0"); ``` ### Step 2: Suppress and Delete Inactive Users ```typescript // scripts/cio-cleanup-inactive.ts import { TrackClient, RegionUS } from "customerio-node"; const cio = new TrackClient( process.env.CUSTOMERIO_SITE_ID!, process.env.CUSTOMERIO_TRACK_API_KEY!, { region: RegionUS } ); interface CleanupTarget { userId: string; reason: string; } async function cleanupInactiveUsers( targets: CleanupTarget[], dryRun: boolean = true ): Promise<void> { let suppressed = 0; let deleted = 0; let errors = 0; for (const target of targets) { if (dryRun) { console.log(`[DRY RUN] Would suppress+delete: ${target.userId} (${target.reason})`); continue; } try { // Step 1: Suppress — stops all messaging immediately await cio.suppress(target.userId); suppressed++; // Step 2: Destroy — removes from billing await cio.destroy(target.userId); deleted++; // Rate limit to 50/sec for bulk operations await new Promise((r) => setTimeout(r, 20)); } catch (err: any) { errors++; console.error(`Failed ${target.userId}: ${err.message}`); } if ((suppressed + errors) % 100 === 0) { console.log(`Progress: ${suppressed} deleted, ${errors} errors`); } } console.log(`\nResult: ${suppressed} suppressed, ${deleted} deleted, ${errors} errors`); } // Usage: Build target list from your database // const inactiveUsers = await db.query(` // SELECT id FROM users // WHERE last_login_at < NOW() - INTERVAL '180 days' // AND email_verified = false // `); ``` ### Step 3: Event Deduplication ```typescript // lib/customerio-dedup-events.ts // Prevent sending duplicate events that inflate volume import { createHash } from "crypto"; import { TrackClient, RegionUS } from "customerio-node"; const cio = new TrackClient( process.env.CUSTOMERIO_SITE_ID!, process.env.CUSTOMERIO_TRACK_API_KEY!, { region: RegionUS } ); // Simple LRU ded
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__customerio-cost-tuning.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Customerio Cost Tuning skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Customerio Cost Tuning safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Customerio Cost Tuning access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Customerio Cost Tuning work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.