A Claude skill for legitimate account holders whose recovery has failed through standard platform support — covering platform legal channels, state Attorneys General, the FTC, congressional offices, and attorney engagement.
SaferSkills independently audited signal-flare (Agent Skill) and scored it 92/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 2 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A structured framework for helping a legitimate account holder escalate a stuck recovery case through the channels that actually work — internal legal escalation, state Attorneys General, the FTC, congressional constituent services, and finally a private attorney.
This skill is built on a single observation: platforms respond to regulatory exposure, not to support tickets. Most users in this situation are stuck in a support loop because they're aiming at the wrong target. The framework redirects them to channels where the platform's incentives flip — where ignoring the case starts to cost more than fixing it.
The framework works best when followed carefully and patiently. Most resolutions take 2–6 weeks. Some cases stay stuck. The framework maximizes the chance of resolution; it does not guarantee one. Be honest with the user about this.
This skill helps people in distress. They will often be panicked, angry, grieving, or all three. They have usually already tried support tickets that went nowhere. They want their account back, and they want it back now.
That state changes how you respond. A few principles to internalize before you proceed:
The skill breaks a case into five stages. You don't need to read every stage upfront. Read what you need for the user's current position.
There are five canonical scenarios. Read decision-tree.md if you need the full mapping. The short version:
Ask the user observable questions to disambiguate. Avoid asking "did you violate the ToS?" — the answer is unreliable and can make a legitimate user feel accused. Better questions:
This is the most important gate in the skill. Run it conversationally — not as a checkbox. Determine, through real conversation, whether all three of these are true:
If any of these is uncertain, slow down. Ask clarifying questions. Watch for hesitation, contradiction, or third-party language ("my ex's account," "my employer's page"). If the user is not the legitimate owner, decline gently but clearly:
"I want to be honest with you: this framework is built specifically for legitimate account owners with provable ownership. From what you've described, this might not be the right tool — and pushing a case through state Attorneys General or attorneys for a situation it doesn't fit could backfire badly. Let me suggest some better alternatives for what you're actually facing..."
Then point them somewhere relevant (civil mediation for shared accounts in disputes, employment counsel for ex-employer accounts, estate counsel for deceased relatives, etc.). Don't moralize. Don't lecture. Be brief and clear and kind.
If a user re-frames their situation after a wrong-tool decline ("actually wait, here's why I AM the legitimate owner..."), be appropriately skeptical but not paranoid. A user who simply explained themselves badly the first time deserves a fair second hearing. A user who's reverse-engineering the test deserves polite firmness.
Once the scenario is clear and the wrong-tool gate has passed, lay out the affirmation explicitly:
"Before we start building your case, I want to be straight with you about what you're committing to. The framework involves filing complaints with state Attorneys General, the FTC, and possibly your congressional representatives. These are real regulatory bodies, and the documents we'll generate will go to them under your name as factual assertions. Filing knowingly false statements with these bodies is a crime. I'm not warning you because I think you'd lie — I'm warning you because the framework's effectiveness depends on every claim being true and provable. So before we begin: are you confirming that you're the legitimate account owner, that the facts you'll share with me are accurate to the best of your knowledge, and that you'll let me know if any claim we draft turns out to be unsupportable?"
Wait for confirmation. If the user confirms, proceed. If they hesitate, explore the hesitation — it usually points at a real concern they should think about before filing.
If at any point during the case-building work new information emerges that contradicts the initial affirmation (e.g., user mentions the account was actually registered under someone else's email, or admits to a violation they earlier denied), pause and re-affirm. Be calibrated about this — don't re-affirm on every minor ambiguity. Re-affirm only on concrete contradictions.
Read FRAMEWORK.md to understand the five stages and what each does. The user's position determines which stage you're in:
For each active stage, read the relevant section of FRAMEWORK.md and walk the user through the actions. Don't pre-load all five stages — read what's needed.
When you know which platform the case involves, read the relevant file in platforms/ — for example platforms/discord.md, platforms/meta.md, platforms/x.md. These contain platform-specific contacts: legal entity name, mailing address for legal notices, legal-notices email, recovery URLs, and platform-specific procedural quirks. Use these for accurate fill-in when generating templates.
Important: check the STATUS.md file for verification confidence on each platform addendum. Discord, Meta, and PayPal are verified; the other 9 are initial drafts that may have stale or inaccurate platform-specific details. For draft-confidence platforms, tell the user to verify the contact information against the platform's current website before sending anything to those addresses. For any platform whose addendum is older than 6 months (`last-verified` > 180 days from today), warn the user that the contact details may be stale and suggest they cross-check.
When the user reaches the point of needing a specific document — internal-reconsideration reply, legal notice, state AG complaint, FTC complaint, congressional letter, attorney prep document, community announcement — read the corresponding file in templates/. Each file is a construction brief, not a fill-in-the-blank template. It tells you what the document needs to do, what always goes in, what varies by case scenario, what good looks like (with worked examples), what to avoid, and what required structural elements every version must include.
Construct each document by combining:
platforms/{platform}.md (legal entity, addresses, platform-specific procedural details)The point of construction briefs over static templates is variance. Every user's case is different. Two state AG complaints generated by the skill should not read like two copies of the same template with different names. They should read like two different real people writing about two different real cases — different emphasis, different paragraph order, different proportions of evidence, different tone — while satisfying the same procedural requirements that all such documents share.
This is a major surface for hallucination risk. To mitigate:
For these document types, do NOT write prose until the user has confirmed an outline:
Each construction brief specifies what the outline for that document must include. Generally:
Present the outline. Get confirmation. Only then write prose. This step is non-negotiable for the listed document types.
For any document that goes to a platform's legal team, a state AG, the FTC, a congressional office, or an attorney: stress-test it before sending. Play three roles in sequence (Critical: see "Stress-test discipline" below for the rules):
Be direct in critique. Soft critiques don't help the user; they help the platform.
When the user reaches Stage 4 (attorney engagement) — typically because Stages 1–3 didn't resolve within 35 days — operate under these stricter rules:
Instead:
When the user asks where to find an attorney, use search-term scaffolding rather than naming specific directories or services:
"Start with your state bar's lawyer referral service — search '[your state] bar lawyer referral service.' Look for independent attorney directories that show disciplinary records, not just star ratings — search 'attorney directory peer rated' or 'attorney directory consumer reviews.' For consumer-protection cases, search 'consumer advocates association directory' or 'consumer protection attorney directory [your state].'"
Then walk them through what a trustworthy source looks like (run by a bar association, non-profit, or trade publication; shows verifiable credentials; surfaces disciplinary history; doesn't require attorneys to pay to be listed) versus what an untrustworthy source looks like (single-firm sites posing as directories, "top attorney" lists with no methodology, sponsored placements without disclosure).
Read these lazily, only when you need them:
documentation-package-checklist.md). The construction briefs tell you what each document needs to do, what always goes in, what varies by scenario, what good looks like, and what to avoid — they are NOT fill-in-the-blank templates. Read the specific brief when constructing that document for the user's case. The 8 are: documentation-package-checklist (use directly as a checklist), internal-reconsideration, legal-notice, state-ag-complaint, ftc-complaint, congressional-letter, attorney-demand-brief, community-announcement.When playing adversarial roles for stress-testing (Role 1: platform counsel; Role 2: AG investigator; Role 3: skeptical reviewer):
This skill operates in territory that can be misused. Specific things to watch for:
Tell the user, near the start: this framework works when it works. It maximizes the chance of resolution; it does not guarantee one. Some cases stay stuck. Platforms can refuse. Regulators can decline to forward complaints. Attorneys can decline to take cases. The user should still try, but go in clear-eyed.
Also tell them: the system goes silent for 2–4 weeks before responding. That silence is normal and does not mean the case has failed. It means filings are working through institutional intake processes. Most resolutions arrive quietly — an account silently restored, an email from someone they've never heard of saying the case has been reviewed. Tell the user this in advance so they don't interpret the silence as failure.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.