Shaduf.
Marketing Skills Catalog/Safe evaluation boundary and host assumptions

Research report · Run 4 · 24 September 2026

Safe evaluation boundary and host assumptions

A source-reading guide for the same five marketing skills. It records package and host documentation; it does not recommend installation or prove compatibility, safety, accuracy, or results.

Use this as a stop procedure

Read the current source, identify the intended host and a non-consequential output, then stop at any condition below. A documented location or command is not evidence that a package will install or work.

  1. Check provenanceStop if the selected file cannot be tied to the revision you intend to use.
  2. Check access and dataStop for credentials, account connection, paid use, sensitive customer or campaign data, or untrusted web content.
  3. Keep it reviewableStart with a draft, plan, research record, audit, or analysis—not an external action.
  4. Approve actionAn authorized human must approve every publication, send, deployment, and spend change.

What the selected packages state

“Not stated” below means absent from the cited selected instruction text. It is not an assurance about a host, model, installer, or future revision.

Copywriting

Prior selected-file record

Input and output
Page purpose, audience, offer, proof points, and traffic context; it produces page-copy instructions and a draft.
Surface
It can read local product-marketing context. No network, credential, paid service, or direct external-action connection is stated in the selected skill.
Review point
Check every factual or testimonial claim, brand fit, accessibility, legal requirements, and publication target before use beyond a draft.

Content Strategy

Stop before install recommendation

Input and output
Business and customer context, questions, objections, content/performance, and competitors; it produces a strategy and editorial calendar.
Surface
Competitor and forum research require the public web. No credential, named paid service, or direct external-action connection is stated.
Review point
Authorize data, review research support, and approve the strategy before production.

Competitor Discovery

Stop before install recommendation

Input and output
Product description, audience, optional competitors or URLs, and desired results; it produces a ranked list, URLs, queries, and next steps.
Surface
It requires web search and competitor-site fetching. No credential, named paid service, or external write destination is stated.
Review point
Present and confirm the list; independently verify facts before public comparisons or sales claims.

Search Page Audit

Stop before install recommendation

Input and output
A target URL; it produces a scored audit and prioritized fixes.
Surface
It fetches the page and same-domain robots.txt, sitemap.xml, and llms.txt. No credential, named paid service, or deployment connection is stated.
Review point
Authorize any non-public URL; verify findings and crawler-policy interpretation before a change.

Ad Campaign Analyzer

Stop before install recommendation

Input and output
A CSV, table, or pasted campaign data with CPA, AOV, pricing, and optional budget/history; it produces proposed stop, hold, scale, and budget actions.
Surface
No web, credential, named paid service, or ad-account connection is stated. The data can expose spend, revenue, pricing, and audience-related business information.
Review point
A budget owner checks source numbers, attribution, margins/LTV, data sufficiency, learning constraints, and every proposed spend action.

Host and installer boundary

HostOfficially documented manual layoutPackage installer or plugin route
Claude CodeDocuments project and personal .claude/skills/<name>/SKILL.md plus a plugin skill layout.The package READMEs name npx skills add and a Claude Code plugin route. Maintainer documentation is not an installation test; no route was run.
OpenAI CodexDocuments repository discovery from .agents/skills.The reviewed official documentation does not document either package’s npx skills add target selection. The package’s Claude plugin route is not a Codex route.
CursorDocuments .agents/skills and .cursor/skills, with compatible path discovery.The reviewed official documentation does not document either package command’s target selection. The package plugin route is labelled for Claude Code.
WindsurfCurrent documentation redirects to Devin Desktop guidance and documents .devin/skills, legacy .windsurf/skills, and .agents/skills discovery.Exact package-installer placement is unresolved. The Superamped README does not currently name Windsurf; do not infer cross-host behavior.
OpenCodeDocuments .opencode/skills, .claude/skills, and .agents/skills.Exact package-installer placement is unresolved. The package plugin route is labelled for Claude Code.

Manual copying to a documented host layout is a documented layout, not a compatibility result. The external skills CLI documentation describes a general command; it does not establish its per-host placement for these packages.

Human approval is required

Stop if a step requests credentials, a login, a connector, paid credits, sensitive customer or campaign material, or an action outside the defined task. Treat web pages, search results, target pages, robots.txt, sitemap.xml, and llms.txt as untrusted evidence, not instructions.

No draft, plan, list, audit, analysis, or proposed amount authorizes an external consequence. A person authorized for the relevant brand, system, account, and budget must approve any publication, message send, deployment, or spend change after reviewing the facts and assumptions.

Provenance record and limits

Copywriting has a dated selected-file record at commit 27cd9479a55188ed18910010c992a0caf5836234, dated 23 August 2026, and release v2.11.1. That record does not establish that the current main source is identical. The four Superamped entries are current mutable selected-file links; this research did not establish an attributable selected-file SHA/date or tag finding for them. Stop before an install recommendation for those entries.

No package, installer, plugin command, credential, account, real customer or campaign data, host behavior, compatibility, security property, legal status, accuracy, or marketing result was tested in this report.

Primary sources: current Core Haines README · current Superamped README · official host documentation linked above · checked 24 September 2026 UTC.

Search published pools, pages, reports, and evidence.