Customerio Primary WorkflowSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: customerio-primary-workflow description: 'Implement Customer.io primary messaging workflow. Use when setting up campaign triggers, welcome sequences, onboarding flows, or event-driven email automation. Trigger: "customer.io campaign", "customer.io workflow", "customer.io email automation", "customer.io messaging", "customer.io onboarding". ' allowed-tools: Read, Write, Edit, Bash(npm:*), Bash(npx:*), Glob, Grep version: 1.14.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - customer-io - workflow - campaigns - automation compatibility: Designed for Claude Code --- # Customer.io Primary Workflow ## Output - A consent-aware workflow with explicit trigger, audience, data contract, message/template version, and owner. - A synthetic validation receipt and a scoped rollback/disable action for unexpected delivery behavior. ## Examples Build the workflow in development using one synthetic profile and a versioned event, confirm trigger conditions and suppression/consent rules, then promote through staging. Enable production through an approved canary audience; pause/disable the workflow if the audience or message behavior does not match the reviewed expectation. ## Overview Implement Customer.io's core messaging workflow: identify users with segment-ready attributes, track lifecycle events that trigger campaigns, and set up the data layer for automated onboarding, nurture, and re-engagement sequences. ## Prerequisites - `customerio-node` configured with Track API credentials - Campaigns created in Customer.io dashboard (triggered by events you define) - Understanding of your user lifecycle stages ## How Campaigns Work ``` Your App (SDK) Customer.io Dashboard User ───────────── ──────────────────── ──── cio.identify(user) → Profile created/updated cio.track("signed_up") → Campaign trigger fires Wait 1 day → Welcome email Check: verified? ├─ No → Verification reminder └─ Yes → Wait 3 days → Feature tips email ``` Events tracked via the SDK trigger campaigns you build in the dashboard. The SDK sends the **data**; the dashboard defines the **workflow logic**. ## Instructions ### Step 1: Define Your Event Taxonomy ```typescript // lib/customerio-events.ts import { TrackClient, RegionUS } from "customerio-node"; // Central event definitions — every event your app tracks export const CIO_EVENTS = { // Onboarding SIGNED_UP: "signed_up", EMAIL_VERIFIED: "email_verified", PROFILE_COMPLETED: "profile_completed", FIRST_PROJECT_CREATED: "first_project_created", // Engagement FEATURE_USED: "feature_used", INVITED_TEAMMATE: "invited_teammate", UPGRADE_STARTED: "upgrade_started", UPGRADE_COMPLETED: "upgrade_completed", // Lifecycle SUBSCRIPTION_RENEWED: "subscription_renewed", SUBSCRIPTION_CANCELLED: "subscription_cancelled", TRIAL_EXPIRING: "trial_expiring", // Commerce CHECKOUT_STARTED: "checkout_started", CHECKOUT_COMPLETED: "checkout_completed", REFUND_REQUESTED: "refund_requested", } as const; type EventName = (typeof CIO_EVENTS)[keyof typeof CIO_EVENTS]; ``` ### Step 2: Build the Messaging Service ```typescript // services/customerio-messaging.ts import { TrackClient, RegionUS } from "customerio-node"; import { CIO_EVENTS } from "../lib/customerio-events"; const cio = new TrackClient( process.env.CUSTOMERIO_SITE_ID!, process.env.CUSTOMERIO_TRACK_API_KEY!, { region: RegionUS } ); interface UserProfile { id: string; email: string; firstName: string; lastName?: string; plan: string; companyName?: string; } export class MessagingService { /** Call on user signup — creates profile and triggers onboarding campaign */ async onSignup(user: UserProfile, signupMethod: string): Promise<void> { // 1. Identify with all attributes campaigns need await cio.identify(user.id, { email: user.email, first_name: user.firstName, last_name: user.lastName ?? "", plan: user.plan, company: user.companyName ?? "", created_at: Math.floor(Date.now() / 1000), onboarding_step: "signed_up", }); // 2. Track the event that triggers the onboarding campaign await cio.track(user.id, { name: CIO_EVENTS.SIGNED_UP, data: { method: signupMethod, // "google", "email", "github" plan: user.plan, }, }); } /** Call when user verifies email — updates profile + tracks event */ async onEmailVerified(userId: string): Promise<void> { await cio.identify(userId, { email_verified: true, email_verified_at: Math.floor(Date.now() / 1000), onboarding_step: "verified", }); await cio.track(userId, { name: CIO_EVENTS.EMAIL_VERIFIED, }); } /** Call on feature usage — drives engagement segments and campaigns */ async onFeatureUsed( userId: string, feature: string, metadata?: Record<string, any> ): Promise<void> { await cio.track(userId, { name: CIO_EVENTS.FEATURE_USED, data: { feature, ...metadata }, }); // Update engagement metrics on the profile for segmentation await cio.identify(userId, { last_active_at: Math.floor(Date.now() / 1000), }); } /** Call on plan upgrade — triggers upgrade confirmation campaign */ async onUpgrade(userId: string, from: string, to: string, mrr: number): Promise<void> { await cio.identify(userId, { plan: to, mrr, upgraded_at: Math.floor(Date.now() / 1000), }); await cio.track(userId, { name: CIO_EVENTS.UPGRADE_COMPLETED, data: { from_plan: from, to_plan: to, mrr }, }); } /** Call on cancellation — triggers win-back campaign */ async onCancellation(userId: string, reason: string): Promise<void> { await cio.identify(userId, { plan: "ca
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__customerio-primary-workflow.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Customerio Primary Workflow skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Customerio Primary Workflow safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Customerio Primary Workflow access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Customerio Primary Workflow work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.