designing-email-templates — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited designing-email-templates (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill when creating or editing email templates for PostHog workflows — broadcast campaigns and function_email workflow actions send the rendered template.
You author the design JSON (content.email.design) and save it with workflows-create-email-template. The server renders the sent email from your design with the same renderer PostHog's visual editor uses, so the template opens as editable blocks for humans and sends exactly what the design describes. Schema and a working example in references/unlayer-design-json.md.
When talking to the user, call it the template's design — the design document format is an internal implementation detail. Always share the template's _posthogUrl edit link in your reply after creating or updating, so the user can open it in PostHog directly.
Read references/design-guidelines.md before composing — it covers committing to a design direction, typography, color, and the patterns that make an email look designed rather than generated. For one fragment the block editor can't express, use an html-type content block inside the design.
Email content uses Liquid templating. Liquid tags pass through the renderer as plain text, so use them anywhere — block text, subject, links:
Hi {{ person.properties.first_name | default: 'there' }},Marketing emails must include an unsubscribe link — render it with the built-in variables:
<a href="{{ unsubscribe_url }}">Unsubscribe</a>({{ unsubscribe_url_one_click }} is also available for one-click list-unsubscribe flows.)
Call workflows-create-email-template with:
{
"name": "Welcome email",
"description": "Sent to new signups on day 0",
"type": "email",
"content": {
"templating": "liquid",
"email": {
"subject": "Welcome to {{ person.properties.company | default: 'our product' }}",
"design": { "counters": { "u_row": 1 }, "schemaVersion": 16, "body": { "rows": ["…"] } },
"text": "Plain-text fallback of the same message"
}
}
}subject is required for email templates.text — it's the fallback for clients that block rich content and improves deliverability.workflows-show-email-template — it renders an inline preview so the user sees the result.Pass the design directly in the tool call — no scratch files, no pre-validation subprocesses, no payload preview rounds. Liquid tags ({{ }}, {% %}), apostrophes, single quotes, and emoji are ordinary characters inside JSON strings; only standard JSON escaping applies. Never rewrite content to avoid them — converting Liquid's single quotes to double quotes inside markup attributes breaks the markup. If the tool call is rejected as malformed, fix the JSON escaping and resend the same content unchanged.
content is replaced as a whole on update, never merged — and humans may have edited the design in PostHog's visual editor since you last saw it:
workflows-get-email-template — always fetch fresh; the returned design is the current source of truth.design (keep subject/text alongside it).workflows-update-email-template — send the complete content back. The server re-renders the sent email from the edited design.workflows-show-email-template — render the updated template so the user sees the change; its response carries the final rendered html, so read it before describing the result.workflows-list-email-templates (metadata only; fetch one for its content).workflows-show-email-template — it renders an inline preview.function_email action, or start a broadcast from it in the PostHog UI.deleted: true via workflows-update-email-template.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.