clix-personalization — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited clix-personalization (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill to help developers write personalized Clix campaigns using template-based variables and light logic in:
user.* (user traits/properties)event.* (event payload properties)trigger.* (custom properties passed via API-trigger)device.id, device.platform, device.locale,device.language, device.timezone, plus user.id, event.name
{{ ... }}.{% if %}, {% else %}, {% endif %} with operators== != > < >= <= and or not. Invalid conditions evaluate to false.
{% for x in y %} / {% endfor %} (use guards for empty lists).upcase, downcase, capitalize, default, join, split,escape, strip, replace (chain with |).
If the Clix MCP tools are available, treat them as the source of truth:
clix-mcp-server:search_docs for personalization behavior and supportedsyntax
If MCP tools are not available, use the bundled references in references/.
Personalization progress:
- [ ] 1) Identify where the template runs (message / URL / audience rule)
- [ ] 2) Identify trigger type (event-triggered vs API-triggered)
- [ ] 3) Confirm available inputs (user.*, event.*, trigger.*, device.*)
- [ ] 4) Draft templates with guards/defaults
- [ ] 5) Validate template structure (balance tags, avoid missing vars)
- [ ] 6) Verify in Clix (preview/test payloads, check Message Logs)Ask only what’s needed:
rule
event.* is availabletrigger.* is availableuser.* properties are set by the appevent.* / trigger.* properties are passed (include examplepayload)
guards)
Return a compact table the user can approve:
size > 0) before looping."7.4 miles","38m 40s") instead of formatting inside templates.
setup.
If you have a template file (recommended for review), run:
bash <skill-dir>/scripts/validate-template.sh path/to/template.liquidThis script does lightweight checks (matching {% if %}/{% endif %}, {% for %}/{% endfor %}, and brace balancing). It can’t guarantee the variables exist — you still need a payload + console verification.
trigger.* (not event.*).user.* is missing → fix user property setting (seeclix-user-management)
event.* is missing → fix event tracking payload (seeclix-event-tracking)
SKILL.md (always loaded)references/ (load when writing/debugging templates)scripts/ (execute directly, do not load into context)references/template-syntax.md - Variables, output, conditionals, loops,filters
references/common-patterns.md - Copy/paste patterns for messages + URLs +guards
references/debugging.md - Troubleshooting missing variables and Message Logs~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.