Customerio Debug BundleSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: customerio-debug-bundle description: 'Collect Customer.io debug evidence for support tickets. Use when creating support requests, investigating delivery failures, or documenting integration issues. Trigger: "customer.io debug", "customer.io support ticket", "collect customer.io logs", "customer.io diagnostics". ' allowed-tools: Read, Grep, Bash(curl:*), Bash(npx:*) version: 1.14.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - customer-io - debugging - support compatibility: Designed for Claude Code --- # Customer.io Debug Bundle ## Output - A minimal redacted diagnostic bundle containing correlation IDs, environment, timestamps, configuration version, and status/error class. - An incident disposition that protects recipient data and credentials while allowing reproduction or vendor escalation. ## Examples For a delivery failure, collect the opaque event/message correlation ID, workspace, timestamp, template/workflow version, and redacted status. Do not export email addresses, full payloads, tokens, or message content. Reproduce with a synthetic profile, then share only the approved redacted bundle with support. ## Current State !`node --version 2>/dev/null || echo 'Node.js: not installed'` !`npm list customerio-node 2>/dev/null | grep customerio || echo 'customerio-node: not installed'` ## Overview Collect a comprehensive debug bundle for Customer.io support tickets: API connectivity tests, user profile inspection, SDK version info, environment validation, and a structured support report. ## Prerequisites - Customer.io API credentials configured - `curl` available for API tests - User ID or email of the affected user/delivery ## Instructions ### Step 1: API Connectivity Diagnostic ```bash #!/usr/bin/env bash set -euo pipefail echo "=== Customer.io Debug Bundle ===" echo "Timestamp: $(date -u +%Y-%m-%dT%H:%M:%SZ)" echo "" # 1. Check Customer.io status echo "--- Platform Status ---" curl -s "https://status.customer.io/api/v2/status.json" \ | python3 -c "import sys,json; d=json.load(sys.stdin); print(f'Status: {d[\"status\"][\"description\"]}')" \ 2>/dev/null || echo "Could not reach status page" # 2. Test Track API authentication echo "" echo "--- Track API Auth ---" TRACK_RESULT=$(curl -s -o /dev/null -w "%{http_code}" \ -u "${CUSTOMERIO_SITE_ID}:${CUSTOMERIO_TRACK_API_KEY}" \ -X PUT "https://track.customer.io/api/v1/customers/debug-test-$(date +%s)" \ -H "Content-Type: application/json" \ -d '{"email":"[email protected]"}') echo "Track API: HTTP ${TRACK_RESULT}" # 3. Test App API authentication echo "" echo "--- App API Auth ---" APP_RESULT=$(curl -s -o /dev/null -w "%{http_code}" \ -H "Authorization: Bearer ${CUSTOMERIO_APP_API_KEY}" \ "https://api.customer.io/v1/campaigns") echo "App API: HTTP ${APP_RESULT}" # 4. DNS and latency echo "" echo "--- Network Diagnostics ---" for host in track.customer.io api.customer.io; do LATENCY=$(curl -s -o /dev/null -w "%{time_total}" "https://${host}") echo "${host}: ${LATENCY}s" done ``` ### Step 2: User Profile Investigation ```typescript // scripts/debug-user.ts // Investigate a specific user's state in Customer.io import { TrackClient, APIClient, RegionUS } from "customerio-node"; async function investigateUser(userId: string) { const cio = new TrackClient( process.env.CUSTOMERIO_SITE_ID!, process.env.CUSTOMERIO_TRACK_API_KEY!, { region: RegionUS } ); console.log(`\n=== User Investigation: ${userId} ===\n`); // Test if we can identify (update) the user — confirms they exist try { await cio.identify(userId, { _debug_checked_at: Math.floor(Date.now() / 1000), }); console.log("Profile: EXISTS (identify succeeded)"); } catch (err: any) { console.log(`Profile: ERROR (${err.statusCode}: ${err.message})`); } // Test if we can track an event on the user try { await cio.track(userId, { name: "debug_check", data: { checked_at: new Date().toISOString() }, }); console.log("Event tracking: WORKING"); } catch (err: any) { console.log(`Event tracking: ERROR (${err.statusCode}: ${err.message})`); } // Check suppression status by trying to unsuppress // (If user is not suppressed, this is a no-op) console.log("\nNote: Check suppression status in Customer.io dashboard:"); console.log(` People > Search "${userId}" > check Suppressed badge`); console.log(" Also check Activity tab for bounce/complaint events"); } const userId = process.argv[2]; if (!userId) { console.error("Usage: npx tsx scripts/debug-user.ts <user-id>"); process.exit(1); } investigateUser(userId); ``` ### Step 3: SDK and Environment Info ```typescript // scripts/debug-env.ts import { readFileSync } from "fs"; function collectEnvInfo() { const report: Record<string, string> = {}; // Node.js version report["node_version"] = process.version; report["platform"] = `${process.platform} ${process.arch}`; // SDK version try { const pkg = JSON.parse( readFileSync("node_modules/customerio-node/package.json", "utf-8") ); report["customerio_node_version"] = pkg.version; } catch { report["customerio_node_version"] = "NOT INSTALLED"; } // Environment config (redacted) report["site_id_set"] = process.env.CUSTOMERIO_SITE_ID ? "YES" : "NO"; report["track_key_set"] = process.env.CUSTOMERIO_TRACK_API_KEY ? "YES" : "NO"; report["app_key_set"] = process.env.CUSTOMERIO_APP_API_KEY ? "YES" : "NO"; report["region"] = process.env.CUSTOMERIO_REGION ?? "us (default)"; // Redacted key prefix for identification const siteId = process.env.CUSTOMERIO_SITE_ID ?? ""; report["site_id_prefix"] = siteId.substring(0, 4) + "..."; console.log("\n=== Environment Debug Info ===\n"); for (const [key, value] of Object.entries(report)) { console.log(`${key}: ${value}`); } } collectEnvInfo(); ``` ### Step 4: Generate Support Report ```typescript // scripts/gener
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__customerio-debug-bundle.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Customerio Debug Bundle skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Customerio Debug Bundle safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Customerio Debug Bundle access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Customerio Debug Bundle work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.