Customerio Load ScaleSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: customerio-load-scale description: 'Implement Customer.io load testing and horizontal scaling. Use when preparing for high traffic, running load tests, or designing queue-based architectures for scale. Trigger: "customer.io load test", "customer.io scale", "customer.io high volume", "customer.io k6", "customer.io performance test". ' allowed-tools: Read, Write, Edit, Bash(npm:*), Bash(npx:*), Bash(kubectl:*), Glob, Grep version: 1.14.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - customer-io - load-testing - scaling - performance compatibility: Designed for Claude Code --- # Customer.io Load & Scale ## Prerequisites - A baseline for event volume, queue depth, latency, error/rate-limit behavior, and an approved load window. - Synthetic payloads, capacity owner, delivery/consent guardrails, and a rollback decision threshold. ## Output - A measured load/capacity result with bounded concurrency, rate-limit behavior, and owner-approved scale decision. - A rollback/recovery record that prevents duplicate or unauthorized customer messaging. ## Examples Run a staged load test using synthetic profiles and fixed idempotency keys, gradually increase only within the provider limit, and record throughput, 429s, queue age, and processing errors. Stop and reduce load on error/ordering regression; never use a live recipient list as a load-test fixture. ## Overview Load testing and scaling strategies for high-volume Customer.io integrations: k6 load test scripts, scaling architecture selection based on volume tier, Kubernetes HPA autoscaling, message queue buffering, and rate-limit-aware batch processing. ## Scaling Architecture by Volume | Daily Events | Architecture | Key Components | |-------------|--------------|----------------| | < 100K | Direct API | Singleton client, retry, connection pooling | | 100K - 1M | Batched API | Event queue, batch processor, rate limiter | | 1M - 10M | Queue-backed | Redis/Kafka queue, worker pool, backpressure | | > 10M | Distributed | Multiple workspaces, sharded queues, regional routing | Customer.io rate limit is ~100 req/sec per workspace. Plan your architecture around this. ## Instructions ### Step 1: k6 Load Test Script ```javascript // load-tests/customerio.js // Run: k6 run --vus 10 --duration 60s load-tests/customerio.js import http from "k6/http"; import { check, sleep } from "k6"; import { Counter, Trend } from "k6/metrics"; const SITE_ID = __ENV.CUSTOMERIO_SITE_ID; const API_KEY = __ENV.CUSTOMERIO_TRACK_API_KEY; const BASE_URL = "https://track.customer.io/api/v1"; const AUTH = `${SITE_ID}:${API_KEY}`; const identifyLatency = new Trend("cio_identify_latency"); const trackLatency = new Trend("cio_track_latency"); const errors = new Counter("cio_errors"); export const options = { scenarios: { identify_load: { executor: "ramping-arrival-rate", startRate: 10, timeUnit: "1s", preAllocatedVUs: 20, maxVUs: 50, stages: [ { duration: "30s", target: 50 }, // Ramp to 50/sec { duration: "60s", target: 80 }, // Hold at 80/sec (near limit) { duration: "30s", target: 10 }, // Cool down ], }, }, thresholds: { cio_identify_latency: ["p(95)<500", "p(99)<2000"], cio_track_latency: ["p(95)<500", "p(99)<2000"], cio_errors: ["count<50"], }, }; export default function () { const userId = `k6-load-${__VU}-${__ITER}`; const headers = { "Content-Type": "application/json", Authorization: `Basic ${encoding.b64encode(AUTH)}`, }; // Identify const identifyRes = http.put( `${BASE_URL}/customers/${userId}`, JSON.stringify({ email: `${userId}@loadtest.example.com`, _load_test: true, created_at: Math.floor(Date.now() / 1000), }), { headers } ); identifyLatency.add(identifyRes.timings.duration); check(identifyRes, { "identify 200": (r) => r.status === 200 }) || errors.add(1); // Track event const trackRes = http.post( `${BASE_URL}/customers/${userId}/events`, JSON.stringify({ name: "load_test_event", data: { iteration: __ITER, vu: __VU }, }), { headers } ); trackLatency.add(trackRes.timings.duration); check(trackRes, { "track 200": (r) => r.status === 200 }) || errors.add(1); sleep(0.1); // Small delay between iterations } // Cleanup function — suppress test users after test export function teardown() { console.log("Load test complete. Clean up k6-load-* users in CIO dashboard."); } ``` Run: ```bash k6 run --env CUSTOMERIO_SITE_ID="$CUSTOMERIO_SITE_ID" \ --env CUSTOMERIO_TRACK_API_KEY="$CUSTOMERIO_TRACK_API_KEY" \ load-tests/customerio.js ``` ### Step 2: Queue-Based Architecture ```typescript // services/cio-queue-worker.ts import { Queue, Worker, QueueEvents } from "bullmq"; import { TrackClient, RegionUS } from "customerio-node"; import Bottleneck from "bottleneck"; const REDIS_URL = process.env.REDIS_URL ?? "redis://localhost:6379"; // Rate limiter: 80 requests per second (leave headroom under 100/sec limit) const limiter = new Bottleneck({ maxConcurrent: 15, reservoir: 80, reservoirRefreshAmount: 80, reservoirRefreshInterval: 1000, }); const eventQueue = new Queue("cio:events", { connection: { url: REDIS_URL }, defaultJobOptions: { attempts: 5, backoff: { type: "exponential", delay: 2000 }, removeOnComplete: { count: 10000 }, removeOnFail: { count: 50000 }, }, }); // Producer — your application enqueues events here export async function enqueueEvent( type: "identify" | "track", userId: string, data: Record<string, any> ): Promise<void> { await eventQueue.add(type, { userId, data, enqueuedAt: Date.now() }); } // Consumer — workers process events with rate limiting export function startEventWorkers(concurrency = 10): void { const cio = new TrackClient( process.env.CUSTOMERIO_SITE_ID!, process.env.CUSTOMERIO_TRACK_API_KEY!, { region: Re
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__customerio-load-scale.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Customerio Load Scale skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Customerio Load Scale safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Customerio Load Scale access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Customerio Load Scale work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.