Atlas / Skills / leoyeai / Selzy Api Skill

Selzy Api SkillSAFE

skills/leoyeai/selzy-api-skill

๐Ÿง  Curated collection of 1209+ best OpenClaw skills โ€” weekly updated by MyClaw.ai

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
2.3
Hosts
1 documented
License
MIT
Stars
2,160
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Full-featured email marketing skill for managing campaigns via Selzy API. Create campaigns, manage contacts, and analyze results directly from chat.

๐Ÿš€ Quick Start

1. Get Selzy API Key

  1. Register at selzy.com
  2. Go to Account Settings โ†’ API
  3. Copy your API key

2. Install Skill (already installed globally)

The skill is already installed in the system. You only need to add the API key.

3. Add API Key to Configuration

# Open OpenClaw config
nano ~/.openclaw/openclaw.json

# Add to env section:
{
"env": {
"SELZY_API_KEY": "your_64_character_api_key"
}
}

# Restart Gateway
openclaw gateway restart

4. Test It

Ask your agent:

Show my contact lists in Selzy

Or:

What's the stats on my last campaign?

๐Ÿ“‹ Features

Contact Management

  • โœ… View all contact lists
  • โœ… Create new lists
  • โœ… Bulk import contacts
  • โœ… Add individual subscribers
  • โœ… Unsubscribe contacts
  • โœ… Custom fields (Company, Phone, etc.)

Campaigns

  • โœ… Create email templates
  • โœ… Instant sending
  • โœ… Scheduled sends
  • โœ… Cancel scheduled campaigns
  • โœ… A/B testing (by creating multiple campaigns)

Analytics

  • โœ… Campaign statistics (opens, clicks, unsubscribes)
  • โœ… Calculate metrics (Open Rate, Click Rate, Bounce Rate)
  • โœ… Compare with previous campaigns
  • โœ… Real-time monitoring

Security

  • โš ๏ธ Never sends campaigns without explicit confirmation
  • โš ๏ธ Verifies sender domains before sending
  • โš ๏ธ Does not expose API key in logs

๐Ÿ’ก Usage Examples

Create a Campaign

Create a campaign for VIP customers with subject "Exclusive Offer"
Text: Hello! Just for you โ€” 30% off all services until end of week.
Send now.

Agent will:

  1. Find "VIP Customers" list
  2. Create email message
  3. Create campaign
  4. Ask for confirmation before sending
  5. Send after your "yes" or "confirm"

Schedule a Webinar

Schedule webinar invitatio
Read from source at commit 4f3b4a2a472eOBSERVED ยท 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
openclawmentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit โ€” this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: selzy
description: >
  Create and send email marketing campaigns via Selzy API.
  Manage contacts, segments, templates. Schedule campaigns,
  run A/B tests, and analyze performance (opens, clicks, bounces).
  Turn natural language requests into full email campaigns.
  
  **v2.1 โ€” Fixed critical bug:** Campaigns now require explicit list_id verification.
  Without list_id, Selzy sends to 1 contact only. Always call getLists first.
metadata:
  openclaw:
    emoji: "โœ‰๏ธ"
    requires:
      env:
        - SELZY_API_KEY
    primaryEnv: SELZY_API_KEY
  version: "2.3"
  lastUpdated: "2026-02-26"
  changelog:
    - "2.3: HARD LIMIT changed to 1 campaign per HOUR (was 1/min) after 35-campaign ban incident"
    - "2.2: Added RATE LIMIT WARNING โ€” max 1 campaign per minute, batch sends forbidden"
    - "2.2: Documented account ban risk: 35 campaigns in few minutes triggered block"
    - "2.1: Added CRITICAL WARNING section about list_id requirement"
    - "2.1: Added SAFETY CHECKLIST for all campaign sends"
    - "2.1: Added real-world bug fix example (1 vs 4 recipients)"
    - "2.1: Updated all workflows to verify contact count before sending"
---

# Selzy Email Marketing API โ€” Complete Guide

Selzy is an email marketing platform with a REST API for managing contacts, creating campaigns, and analyzing performance. This skill lets you run your entire email marketing from an AI assistant.

---

## ๐Ÿšจ CRITICAL WARNING โ€” Read Before Using

### โš ๏ธ Common Pitfall: Campaigns Sent to Wrong Recipients

**Problem:** If you create a campaign without explicitly specifying `list_id`, Selzy will send to **ONLY 1 contact** (default behavior), not your entire list.

**Solution:** ALWAYS follow this workflow:
1. Call `getLists` โ†’ get the correct `list_id` AND verify contact count
2. Pass `list_id` to `createEmailMessage` (REQUIRED parameter)
3. Verify recipient count matches expectations BEFORE calling `createCampaign`
4. Get explicit user confirmation before sending

**This affects ALL users.** The fix is in the workflow, not the API.

---

### ๐Ÿšซ RATE LIMIT WARNING โ€” Account Ban Risk

**REAL INCIDENT (2026-02-25):** User sent **35 email campaigns in a few minutes** using `createCampaign`. Selzy blocked the account for suspicious bulk activity.

**Official Selzy API Rate Limits** (from https://selzy.com/en/support/api/common/selzy-api-limits/):

| Endpoint / Action | Limit |
|-------------------|-------|
| **General API** | 1200 requests / 60 seconds (per API key or IP) |
| **checkEmail method** | 300 requests / 60 seconds |
| **subscribe method** | Limited (exact value not published) |
| **sendEmail method** | 1,000 emails/day default for new users (auto-increases) |
| **sendSms method** | 150 numbers per call |
| **getCampaigns method** | 10,000 campaigns per response |
| **getMessages limit** | 100 records per request (default 50) |
| **importContacts timeout** | 30 seconds per call |

**โš ๏ธ CRITICAL: Campaign Creation Rate (UNPUBLISHED but ENFORCED)**

While general API allows 1200 req/min, **creating campaigns (`createCampaign`) has additional fraud detection**:
- **MAX 1 campaign creation per HOUR** (strict limit after ban incident)
- **Burst of 35 campaigns in <5 min = instant account block** (real incident 2026-02-25)
- Selzy's fraud system flags rapid campaign creation as suspicious bulk activity

**Why the discrepancy?**
- 1200 req/min is for **read operations** (getLists, getCampaigns, stats)
- **Write operations** (createCampaign, importContacts) have stricter anti-abuse limits
- No official documentation on campaign creation rate โ€” enforced heuristically

**Symptoms of Rate Limit Violation:**
- API returns `count=0` for all campaigns (even valid ones)
- Campaigns stuck in `scheduled` status but never send
- Account flagged for manual review

**Recovery:**
1. **STOP all campaign creation immediately**
2. Wait 24-48 hours for automatic unblock OR contact Selzy support
3. Request manual review + explain it was automation error
4. When unblocked: implement rate limiting (**1 campaign / hour MAX**)

**Prevention:**
- **Wait 1 HOUR between `createCampaign` calls** โ€” this is now the hard limit
- For batch sends: create max 1 campaign per hour, spread across days
- Monitor API responses: `count=0` across multiple campaigns = RED FLAG
- **NEVER automate bulk campaign creation without rate limiting**
- Remember: 1200 req/min is for READ operations, not campaign creation

**If you need to send to multiple segments:**
```
1. Create all email messages first (no rate limit on createEmailMessage)
2. Schedule campaigns across multiple days (1 per hour max)
3. OR: use single campaign with segmented list (preferred)
4. Use cron jobs with hourly spacing for automated sends
```

**This is now MANDATORY:** Any automation creating >1 campaign per hour will risk permanent ban. **1 campaign per hour = HARD LIMIT.**

---

### ๐Ÿ“Š Official Selzy API Limits Summary

| Operation | Limit | Notes |
|-----------|-------|-------|
| General API calls | 1200 / min | Per API key or IP |
| checkEmail | 300 / min | Email validation |
| sendEmail (transactional) | 1000 / day | New users, auto-increases |
| sendSms | 150 / call | Max numbers per request |
| getCampaigns | 10,000 / response | Pagination needed for more |
| getMessages | 100 / request | Default 50 |
| importContacts | 30s timeout | Per call |
| **createCampaign** | **1 / hour** | **Unpublished, HARD LIMIT after ban incident** |

**Source:** https://selzy.com/en/support/api/common/selzy-api-limits/

---

## ๐Ÿ” Authentication

All requests require the `SELZY_API_KEY` environment variable. Pass it as the `api_key` parameter.

**Base URL:** `https://api.selzy.com/en/api`

**Important:** All methods use `GET` with query parameters (Selzy API uses GET for all endpoints). URL-encode parameter values when needed.

## General Request Pattern

```bash
curl "https://api.selzy.com/en/api/{METHOD}?format=json&api_key=$SELZY_API_KEY&{params}"
```

**Response Format:**
- Success: `{"re
04

Trust audit

SAFEgrade B ยท trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

MEDIUMObfuscation / stealth ยท obf.base64_blob ยท CWE-506, CWE-94
skills/compdf-conversion-cli/scripts/license.xml:9
<key>k5Ey9KFlkqpj+SDkUw+5ED9lTA3En/qUi0zdrydUCH3kMWTE3Eh65NXnFCaxlY2omY2JHnlEoK7Li7oOEvM7eG5VPdcO/sFlMfoCRdnLYdepJ+uLzYwOWR8W4yQVve/clxVFTVRL4DFleKInGdpAxIbHZT2yi4ADAMENls1N1XSLojRuqXePXDeAT/4Mv4TTx0s

Gates applied: no_behavioural_pass.

Audited 2026-10-08 ยท audit v0.4.1 ยท source sha 4f3b4a2a472efull audit observations/trust-audit/skill/leoyeai__selzy-api-skill.json ยท Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f3b4a2a472eSAFEB89first audit
06

Questions

What does the Selzy Api Skill skill do?

๐Ÿง  Curated collection of 1209+ best OpenClaw skills โ€” weekly updated by MyClaw.ai

Is Selzy Api Skill safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Selzy Api Skill access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Selzy Api Skill work with?

Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f3b4a2a472e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes โ€” this is the first audit.

Advertisement