Developer documentationSkill

Once Email Skill

Stop rebuilding fragile email waits in every test suite

test-email-flows helps an agent add one reviewed workflow to an application you own or are authorized to test. It checks prerequisites, plans without side effects, waits within one deadline, requires a unique match, returns redacted evidence, and cleans up on success or failure.

Open-source versioned Skill prerelease available

What it solves

Before: every project rewrites polling, matching, error handling, and cleanup.

With the Skill: doctor, plan, one bounded test, and explicit recovery.

After: CI receives a useful redacted result instead of “email not found”.

Built for three common authorized flows

Verification-code email

Confirmation-link delivery

Notification and delivery assertions

doctor → plan → run → cleanup

$test-email-flows
doctor
plan
run one authorized flow
require cleanup=cleaned

Safe automation scope

Create an isolated inbox, poll with a deadline, match a test marker, read the target message, assert the result, and delete the inbox. Every step needs a timeout, quota, and cleanup outcome.

Data that must stay out of model context

API keys, full addresses, verification codes, confirmation links, bodies, attachments, cookies, and session identifiers must not enter prompts, ordinary logs, or ordinary analytics.

Skill responsibility

A Skill may orchestrate reviewed API operations, enforce redaction, and return a minimal test result. It must not replace authorization checks or enable account abuse, policy evasion, or third-party monitoring.

A result CI can trust

Keep timeout, ambiguity, extraction, assertion, and cleanup failures distinct, then return only redacted evidence that identifies the real failure.

Recommended integration flow

  1. Proceed only with explicitly authorized API access and already issued, valid credentials with the minimum necessary permissions. Store them in a process secret facility; without this access, stop at reviewing the documentation and downloads.
  2. Create one isolated inbox per test.
  3. Trigger mail only from an authorized system.
  4. Poll with backoff and a fixed deadline.
  5. Return only a redacted assertion result.
  6. Delete the inbox on success or failure.

Prompt + Demo

Safe prompts and an authorized-project demo

Never paste keys, addresses, OTPs, links, or message content.

Complete usage guide

Download the versioned local bundle

Use only an application you own or are explicitly authorized to test. Once Email receives mail only; it does not send mail or automate third-party registrations.

Documentation and source are public. API calls remain controlled. SDKs and the Skill are versioned prerelease downloads, not language-registry releases. Public documentation and prerelease downloads do not grant API access. API key creation and live calls are not publicly open.

Open SHA256SUMS before extracting the file.

Exact local starting point

unzip test-email-flows-0.1.0-private.2.zip

From download to a clean first run

  1. Download the complete Skill bundle and verify its checksum.
  2. Install the whole test-email-flows folder in the agent Skills directory; do not copy only SKILL.md.
  3. Reload the agent and confirm the Skill is discoverable before opening the authorized project.
  4. Keep the key and all email data outside chat; invoke $test-email-flows and run doctor then plan.
  5. Proceed only with explicitly authorized API access and already issued, valid credentials with the minimum necessary permissions. Store them in a process secret facility; without this access, stop at reviewing the documentation and downloads. Run exactly one flow with trace, video, and screenshots disabled.
  6. Require cleanup=cleaned; never open or quote the local 0600 cleanup journal.

Failure and recovery

Keep 400, 401, 403, 404, 413, 429, and 503 distinct. Timeout, ambiguity, extraction, assertion, and cleanup are also different failures. Retry only within one deadline and never turn a dependency failure into an empty inbox.