{"id":"6d39557b-1f2f-48de-ab1b-9949d673f1d0","entityType":"agent","slug":"clawhub-jwestburg-resend-send-native-node","name":"resend-send-native-node","canonicalUrl":"https://www.xpersona.co/agent/clawhub-jwestburg-resend-send-native-node","canonicalPath":"/agent/clawhub-jwestburg-resend-send-native-node","generatedAt":"2026-10-10T10:43:00.422Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:27:05.264Z","emptyReason":null},"description":"Send email via Resend.com's HTTPS API - native Node.js, zero dependencies. Use when the user explicitly asks to email, send a message, mail a report, or deliver a notification to an email address. Externally sends email only with --send; defaults to dry-run and requires RESEND_ALLOWED_TO allowlist for real sends. Requires RESEND_API_KEY in the process environment for real sends. No OAuth, no 2FA, no Gmail required.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.7K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s177the448m6rk54wz8gse0jnd8587yq:resend-send-native-node","sourceUrl":"https://clawhub.ai/jwestburg/resend-send-native-node","homepage":"https://clawhub.ai/jwestburg/skills/resend-send-native-node","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/jwestburg/resend-send-native-node","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/jwestburg/skills/resend-send-native-node","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":64,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"resend-send-native-node technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:27:05.264Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:27:05.264Z","emptyReason":null},"stars":null,"forks":null,"downloads":1655,"packageName":null,"latestVersion":"1.0.20","tractionLabel":"1.7K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:27:05.264Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T05:27:05.264Z","lastCrawledAt":"2026-10-10T05:27:05.264Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T05:27:05.264Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.20","createdAt":"2026-09-11T02:26:46.437Z","changelog":"Public candidate v1.0.20: reviewed Resend send-only helper with dry-run default, explicit send gate, recipient allowlist, JSON receipts, and no-send local tests.","fileCount":5,"zipByteSize":13929},{"version":"1.0.15","createdAt":"2026-07-15T20:39:36.188Z","changelog":"Document the actual no-send publish/update checks, including the existing tests\\\\run-resend-send-tests.mjs runner, so public update gates do not rely on a nonexistent self-test path. No send behavior change.","fileCount":5,"zipByteSize":11243},{"version":"1.0.12","createdAt":"2026-06-14T22:43:41.586Z","changelog":"ClawHub publication/version refresh after JSON receipt fix and public-readiness review; no additional runtime behavior change.","fileCount":5,"zipByteSize":10838},{"version":"1.0.10","createdAt":"2026-06-12T13:53:52.660Z","changelog":"Clarify explicit approval must cover to/cc/bcc/from/reply-to/subject/body before real sends; no code changes.","fileCount":5,"zipByteSize":9987},{"version":"1.0.9","createdAt":"2026-06-02T03:57:30.748Z","changelog":"Public-ready safety/docs/test update","fileCount":5,"zipByteSize":9824},{"version":"1.0.8","createdAt":"2026-05-30T19:26:51.339Z","changelog":"Add timeout/duplicate-send caveats, fix fail-closed samples, and soften public Resend account/default-sender wording.","fileCount":4,"zipByteSize":8660},{"version":"1.0.6","createdAt":"2026-05-26T02:48:26.752Z","changelog":"Add version metadata, hedged rate-limit wording, Windows 403 cleanup assertion note, and sanitized dry-run/fail-closed sample outputs.","fileCount":4,"zipByteSize":8041},{"version":"1.0.5","createdAt":"2026-05-08T15:42:21.161Z","changelog":"Replace placeholder sender example with generic verified-domain wording after final public review.","fileCount":3,"zipByteSize":6004}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s177the448m6rk54wz8gse0jnd8587yq:resend-send-native-node","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s177the448m6rk54wz8gse0jnd8587yq:resend-send-native-node` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/jwestburg/resend-send-native-node before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-resend-send-native-node/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-resend-send-native-node/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-resend-send-native-node/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-resend-send-native-node/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-resend-send-native-node/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-resend-send-native-node/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T10:43:00.419Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-resend-send-native-node/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-resend-send-native-node/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-resend-send-native-node/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-resend-send-native-node/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:27:05.264Z","emptyReason":null},"readme":"Skill: resend-send-native-node\n\nOwner: jwestburg\n\nSummary: Send email via Resend.com's HTTPS API - native Node.js, zero dependencies. Use when the user explicitly asks to email, send a message, mail a report, or deliver a notification to an email address. Externally sends email only with --send; defaults to dry-run and requires RESEND_ALLOWED_TO allowlist for real sends. Requires RESEND_API_KEY in the process environment for real sends. No OAuth, no 2FA, no Gmail required.\n\nTags: email:1.0.8, email resend notifications reports nodejs no-deps send-only:1.0.3, latest:1.0.20, no-deps:1.0.8, node:1.0.8, notifications:1.0.8, reports:1.0.8, resend:1.0.8, send-only:1.0.8\n\nVersion history:\n\nv1.0.20 | 2026-09-11T02:26:46.437Z | user\n\nPublic candidate v1.0.20: reviewed Resend send-only helper with dry-run default, explicit send gate, recipient allowlist, JSON receipts, and no-send local tests.\n\nv1.0.15 | 2026-07-15T20:39:36.188Z | user\n\nDocument the actual no-send publish/update checks, including the existing tests\\\\run-resend-send-tests.mjs runner, so public update gates do not rely on a nonexistent self-test path. No send behavior change.\n\nv1.0.12 | 2026-06-14T22:43:41.586Z | user\n\nClawHub publication/version refresh after JSON receipt fix and public-readiness review; no additional runtime behavior change.\n\nv1.0.10 | 2026-06-12T13:53:52.660Z | user\n\nClarify explicit approval must cover to/cc/bcc/from/reply-to/subject/body before real sends; no code changes.\n\nv1.0.9 | 2026-06-02T03:57:30.748Z | user\n\nPublic-ready safety/docs/test update\n\nv1.0.8 | 2026-05-30T19:26:51.339Z | user\n\nAdd timeout/duplicate-send caveats, fix fail-closed samples, and soften public Resend account/default-sender wording.\n\nv1.0.6 | 2026-05-26T02:48:26.752Z | user\n\nAdd version metadata, hedged rate-limit wording, Windows 403 cleanup assertion note, and sanitized dry-run/fail-closed sample outputs.\n\nv1.0.5 | 2026-05-08T15:42:21.161Z | user\n\nReplace placeholder sender example with generic verified-domain wording after final public review.\n\nv1.0.4 | 2026-05-07T22:17:09.180Z | user\n\nFix ClawHub listing tags; no runtime changes.\n\nv1.0.3 | 2026-05-06T15:51:02.599Z | user\n\nScanner-surface reduction: remove body-file support and local file reads; message body must be reviewed and passed with --body.\n\nv1.0.2 | 2026-05-06T15:14:38.508Z | user\n\nDisplay-name consistency: remove parentheses from Native Node to match other jwestburg skills.\n\nv1.0.1 | 2026-05-06T15:11:05.946Z | user\n\nPublic-package hygiene: remove local .env credential fallback; use process environment only. Listing polished with PowerShell examples and ASCII-safe copy.\n\nArchive index:\n\nArchive v1.0.20: 5 files, 13929 bytes\n\nFiles: scripts/send.mjs (12694b), skill-card.md (2642b), SKILL.md (15935b), tests/run-resend-send-tests.mjs (8233b), _meta.json (143b)\n\nFile v1.0.20:SKILL.md\n\n---\nname: resend-send-native-node\ndescription: Send email via Resend.com's HTTPS API - native Node.js, zero dependencies. Use when the user explicitly asks to email, send a message, mail a report, or deliver a notification to an email address. Externally sends email only with --send; defaults to dry-run and requires RESEND_ALLOWED_TO allowlist for real sends. Requires RESEND_API_KEY in the process environment for real sends. No OAuth, no 2FA, no Gmail required.\nversion: 1.0.20\nrisk_class: external-email-send-dry-run-default-send-gated\n---\n\n# Resend Send Native Node\n\nSend email via the Resend.com HTTPS API.\n\nNative Node.js. Zero dependencies. One POST call for real sends. Small enough to audit directly.\n\n## When to use\n\nTrigger phrases: \"email me\", \"send an email\", \"mail this to\", \"send a notification\", \"email the report\".\n\n**Use this when:**\n- The user wants to send an email fast, without Gmail OAuth or App Password pain\n- Simple \"fire and forget\" sends (no inbox reading needed)\n- The user has a Resend.com account (check Resend's current pricing/limits before relying on a specific quota)\n- Weekly/report-style outbound messages where the body is generated from explicitly reviewed text\n\n**Do NOT use this when:**\n- The user wants to READ email (this is send-only)\n- The user needs to send from a specific personal Gmail address (use a Gmail-specific skill)\n- Sensitive business emails where provenance matters (Resend's default `onboarding@resend.dev` sender looks transactional)\n- The recipient, sender, or final body has not been explicitly reviewed/approved for a real send\n\n## Safety policy for agents\n\nThis skill is send-only, but it is still externally mutating. For agent use:\n\n1. **Draft first.** Generate or inspect the exact body text before sending.\n2. **Dry-run first.** The script dry-runs by default; review the printed payload.\n3. **Explicit approval.** Use `--send` only after the user explicitly approves the exact `to`, `cc`, `bcc`, `from`, `reply-to`, `subject`, and body. Treat `reply-to` as response-routing control and review display-name text in `from` for spoof-like wording before any real send.\n4. **Use an allowlist.** Real sends fail closed unless `RESEND_ALLOWED_TO=addr@example.com,other@example.com` is set in the process environment for approved recipients. Treat `RESEND_ALLOWED_TO` as an operator-controlled, approval-scoped guard; agents must not broaden or set it merely to make a send succeed unless the user explicitly approves that exact allowlist change.\n5. **No raw memory dumps.** Email only curated report text, not unfiltered memory, transcripts, logs, or private workspace context.\n\n## How to run\n\nThe script is in `scripts/send.mjs`. Requires Node.js 18+ because real sends use native `fetch` and `AbortController`.\n\nFor operator workflows, prefer `--json` so dry-runs and real sends produce a stable machine-readable receipt with `mode`, `sent`, recipients, subject, body byte count, full body SHA-256, SHA-256 prefix, allowlist status, and `resendId` on successful real sends.\n\n### Agent-safe invocation boundary\n\nFor agent-generated, user-supplied, multiline, or otherwise arbitrary `subject`, `body`, `from`, `reply-to`, `to`, `cc`, or `bcc` values, **do not interpolate those values into a shell command string**. Shell quoting is outside this script's control and can be broken before the script's dry-run, allowlist, or approval gates execute.\n\nCanonical agent path: invoke Node directly with an argv array and pass reviewed message fields as one JSON object on stdin with `--input-json-stdin`. Keep mode flags such as `--dry-run`, `--send`, and `--json` in argv; the stdin JSON payload accepts only message fields and cannot set send mode.\n\nExample argv shape for agents/orchestrators:\n\n```text\nargv: [\"<skill-dir>/scripts/send.mjs\", \"--json\", \"--dry-run\", \"--input-json-stdin\"]\nstdin JSON: {\"to\":[\"you@example.com\"],\"subject\":\"Reviewed subject\",\"body\":\"Approved body text\"}\n```\n\nThe shell examples below are for simple literal operator commands only. They are not the safe transfer path for arbitrary generated content.\n\n**Basic:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n```\n\nWithout `--send`, this prints a dry-run payload and does **not** send. Dry-run output includes the full reviewed body JSON plus body byte length and SHA-256 prefix; redact dry-run logs before sharing externally.\n\n**With from address override:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --from \"Example Sender <onboarding@resend.dev>\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi\"\n```\n\n**HTML body:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --html --to \"you@example.com\" --subject \"Styled\" --body \"<h1>Hi</h1><p>Hello</p>\"\n```\n\n**Dry run (no send, just print the payload):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --dry-run --to \"you@example.com\" --subject \"Test\" --body \"...\"\n```\n\nIf `--dry-run` and `--send` are both present, dry-run wins and no email is sent.\n\n**Real send (only after explicit approval):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --send --to \"you@example.com\" --subject \"Weekly report\" --body \"Approved report text\"\n```\n\n### All flags\n\n| Flag | Required? | Purpose |\n|---|---|---|\n| `--to` | yes unless supplied by `--input-json-stdin` | Comma-separated recipient addresses |\n| `--subject` | yes unless supplied by `--input-json-stdin` | Message subject |\n| `--body` | yes unless supplied by `--input-json-stdin` | Inline message body; use stdin JSON instead for agent-generated or arbitrary text |\n| `--cc` | no | Comma-separated cc |\n| `--bcc` | no | Comma-separated bcc |\n| `--from` | no | Override sender, e.g. `\"Example Sender <onboarding@resend.dev>\"` |\n| `--reply-to` | no | Reply-to address |\n| `--html` | no | Body is HTML instead of plain text |\n| `--dry-run` | no | Don't send; print the JSON payload |\n| `--send` | no | Actually send. Without this, the script dry-runs by default |\n| `--json` | no | Print a stable JSON receipt for dry-run or real send |\n| `--input-json-stdin` | no | Read message fields from one JSON object on stdin; preferred for agent-generated/arbitrary text because it avoids shell interpolation |\n| `-h`, `--help` | no | Show help |\n\nRecipients in `--to`, `--cc`, `--bcc`, and `--reply-to` must be bare email addresses. Only `--from` accepts display-name format such as `\"Reports <reports@example.com>\"`.\n\n`--body-file` is intentionally not supported in the public package. Review file contents yourself and pass approved text with `--body`, or for agent workflows pass the exact reviewed message fields through `--input-json-stdin` without shell interpolation.\n\n## Credentials\n\nRequires process environment values:\n\n- `RESEND_API_KEY` - starts with `re_...`\n- `RESEND_ALLOWED_TO` - comma-separated recipient allowlist for real sends\n- Real sends require `RESEND_ALLOWED_TO`; without it the script refuses `--send`\n- Treat `RESEND_ALLOWED_TO` as operator-controlled. Setting or widening it is a separate approval-scoped action, not something an agent should do automatically to satisfy `--send`.\n\n**How to get one:**\n1. Sign up at https://resend.com and check the current pricing/limits for the account\n2. Go to **API Keys** in the dashboard\n3. Click **Create API Key**, name it, and choose the least-privilege sending permission available for your account\n4. Copy the key\n\nExport it in the runtime process environment:\n```powershell\n$env:RESEND_API_KEY=\"<your-resend-key>\"\n$env:RESEND_ALLOWED_TO=\"you@example.com,reports@example.com\"\n```\n\n## Sender identity\n\nBy default, emails are sent from `onboarding@resend.dev` - Resend's default sender. This may support quick testing subject to current Resend account restrictions; use a verified domain/sender for production-style mail.\n\n**For a custom domain (later, optional):**\n1. Add your domain to Resend at https://resend.com/domains\n2. Configure DNS records they provide\n3. Use a verified sender with `--from \"Reports <reports@your-verified-domain.example>\"`\n\n## What this skill does\n\n- Reads `RESEND_API_KEY` from the process environment only\n- POSTs a JSON request to the fixed endpoint `https://api.resend.com/emails` with redirects disabled\n- Prints a one-line confirmation with the Resend message ID\n- Defaults to dry-run unless `--send` is present\n- Validates basic recipient address shape before sending\n- Enforces `RESEND_ALLOWED_TO` for real sends; fail-closed if it is missing\n- Prints body byte length and SHA-256 prefix in dry-run so reviewed content can be matched to the send\n- Supports `--json` receipt output so automation can compare the reviewed body hash to the send receipt and capture `resendId` without scraping human text\n\n## What this skill does NOT do\n\n- Does not read or manage email (this is send-only)\n- Does not read local files or support `--body-file`\n- Does not write any files\n- Does not intentionally make network calls other than the fixed `https://api.resend.com/emails` request; redirects are disabled with `redirect: \"error\"`\n- Does not auto-update\n- Does not support attachments in this version\n\n## Output\n\nOn success:\n```\nsent to you@example.com (subject: Hello) - resend-id: c8f43f2a-...\n```\n\nWith `--json`, dry-runs and sends emit parseable JSON. Successful real sends include `sent: true`, `bodySha256`, `bodySha256Prefix`, and `resendId`.\n\nOn failure, clear error on stderr with a non-zero exit code.\n\n## Troubleshooting\n\n- **\"RESEND_API_KEY not set\"** - create one at https://resend.com, check current pricing/limits, and export `RESEND_API_KEY` in the process environment\n- **HTTP 401** - API key is invalid or was revoked\n- **HTTP 403** - API key doesn't have send permission, or the from address can only send to the account owner until a domain is verified (check dashboard). On Windows, a Node.js cleanup assertion may appear after a 403 exit; this is cosmetic and does not indicate a successful send.\n- **HTTP 422** - the from address isn't verified on your Resend account (use `onboarding@resend.dev` or verify your own domain)\n- **HTTP 429** - rate limited; check https://resend.com/pricing or the Resend dashboard for current limits\n- **HTTP 5xx** - Resend/server-side failure or ambiguity; if the request may have reached Resend, check the dashboard before retrying to avoid duplicate sends.\n- **Network error or timeout** - transient, but a network/timeout/read error after the request was sent does not prove the email was not delivered. Check the Resend dashboard before retrying to avoid duplicate sends.\n\n## Sample output\n\nSanitized representative output for eval/review checks:\n\n```text\n$ node scripts/send.mjs --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n--- DRY RUN: request would be sent ---\nnote: add --send to perform a real send after explicit approval.\nbody: 8 bytes, sha256:8328c36d18b7\nWARNING: RESEND_ALLOWED_TO is not configured. Real sends will fail closed until an allowlist is set.\nPOST https://api.resend.com/emails\nAuthorization: Bearer [redacted]\n\n{\n  \"from\": \"onboarding@resend.dev\",\n  \"to\": [\n    \"you@example.com\"\n  ],\n  \"subject\": \"Hello\",\n  \"text\": \"Hi there\"\n}\n\n$ node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\nerror: RESEND_ALLOWED_TO must be set for real sends. Refusing --send without a recipient allowlist.\n\n# PowerShell:\n# Only set or widen RESEND_ALLOWED_TO after explicit approval for that exact allowlist change.\n$env:RESEND_ALLOWED_TO=\"you@example.com\"; node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n# bash/zsh:\n# RESEND_ALLOWED_TO=\"you@example.com\" node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\nerror: RESEND_API_KEY not set in process environment. Create one at https://resend.com, check current pricing/limits, and export RESEND_API_KEY.\n```\n\n## Required checks before publishing/updating\n\nMinimum no-send checks:\n\n```powershell\nnode --check skills\\resend-send-native-node\\scripts\\send.mjs\nnode skills\\resend-send-native-node\\scripts\\send.mjs --help\nnode skills\\resend-send-native-node\\scripts\\send.mjs --to \"test@example.com\" --subject \"Smoke\" --body \"Hello\" --json\nnode skills\\resend-send-native-node\\tests\\run-resend-send-tests.mjs\n```\n\nThe smoke command above must remain a dry-run: do not include `--send`. Real sends require separate explicit approval for the exact recipient headers, subject, and body plus an allowlist.\n\n## Account limits\n\nResend pricing and free-tier limits can change. Check the current Resend dashboard/pricing page before relying on a specific daily/monthly quota or paid-tier price. New accounts commonly support quick testing from `onboarding@resend.dev`; use a verified domain/sender for production-style mail.\n\n## Changelog\n\n- `1.0.20`: Mirror the operator-controlled `RESEND_ALLOWED_TO` warning in CLI help and document 5xx retry ambiguity/support guidance. No send behavior change.\n- `1.0.19`: Make `RESEND_ALLOWED_TO` ownership explicit: it is an operator-controlled, approval-scoped guard, and agents must not set or widen it merely to make a send succeed. No send behavior change.\n- `1.0.18`: Clarify the flags table/help that required message fields may be supplied through `--input-json-stdin` instead of inline flags, so support handoffs do not steer arbitrary generated/user content through shell interpolation. No send behavior change.\n- `1.0.17`: Add canonical `--input-json-stdin` agent invocation path for arbitrary reviewed message fields, document that agents must not shell-interpolate generated email content, add hostile metacharacter stdin regression coverage, and enforce fixed-endpoint no-redirect behavior with `redirect: \"error\"`. No real-send approval semantics changed.\n- `1.0.16`: Add committed no-send regression coverage for `--dry-run --send` precedence and `cc`/`bcc` allowlist blocking before any API-key/fetch path. No send behavior change.\n- `1.0.15`: Document the actual no-send publish/update checks, including the existing `tests\\run-resend-send-tests.mjs` runner, so public update gates do not rely on a nonexistent self-test path. No send behavior change.\n- `1.0.14`: Public package eval hygiene: generate the Resend API-key-shaped test sentinel at runtime so package scanners do not see a static key-shaped string in source; no send behavior change.\n- `1.0.13`: Source-polish retest prep: genericized a review fixture subject, documented that `--dry-run --send` resolves to dry-run, and normalized SKILL.md line endings; no send behavior change.\n- `1.0.12`: ClawHub publication/version refresh after JSON receipt fix and public-readiness review; no additional runtime behavior change.\n- `1.0.11`: Add `--json` structured receipts for dry-run and real send output so operators can capture stable subjects, body hashes, allowlist status, and `resendId` without scraping human text.\n- `1.0.10`: Clarify explicit approval must cover all delivery/reply headers (`to`, `cc`, `bcc`, `from`, `reply-to`), subject, and body before real sends.\n- `1.0.9`: Add explicit Node.js 18+ usage prerequisite and offline gate-regression tests for dry-run, allowlist fail-closed, missing-key fail-closed, HTML/reply-to payloads, unsupported body-file, invalid recipients, and help output.\n- `1.0.8`: Soften public Resend account/default-sender wording to avoid stale pricing/free-tier/domain-setup assumptions.\n- `1.0.7`: Fix no-allowlist sample output, document bare-recipient requirement and dry-run body visibility, add 30s send timeout, and warn to verify Resend dashboard before retrying ambiguous network/timeout failures.\n- `1.0.6`: Add frontmatter version metadata, hedge rate-limit wording, document Windows 403 cleanup assertion behavior, and include sanitized dry-run/fail-closed sample outputs for eval review.\n- `1.0.5`: Public package wording and metadata cleanup; send behavior remains dry-run-first with `--send` plus recipient allowlist required for real sends.\n\nFile v1.0.20:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"resend-send-native-node\",\n  \"version\": \"1.0.20\",\n  \"publishedAt\": 1789093606437\n}\n\nFile v1.0.20:skill-card.md\n\n## Description:\n\nResend Send Native Node sends email via Resend.com's HTTPS API using native Node.js, with dry-run defaults and gated real sends.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jwestburg](https://clawhub.ai/user/jwestburg)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill when a user explicitly asks to send an email, message, report, or notification through Resend. It supports previewing the exact payload before delivery and requires explicit send approval plus a recipient allowlist for real sends.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Real email sends are externally mutating and may deliver incorrect or unapproved content.\n\nMitigation: Draft and dry-run first, review the exact recipients, headers, subject, and body, and use --send only after explicit user approval.\n\nRisk: Emailing raw logs, transcripts, secrets, or private workspace context can expose sensitive information through Resend.\n\nMitigation: Send only curated, reviewed content that the user is comfortable transmitting externally.\n\nRisk: A broad or agent-modified recipient allowlist can bypass the intended recipient control for real sends.\n\nMitigation: Keep RESEND_ALLOWED_TO narrow and operator-controlled, and do not widen it merely to make a send succeed.\n\nRisk: Network timeouts or server-side errors can leave delivery status ambiguous and cause duplicate emails if retried blindly.\n\nMitigation: Check the Resend dashboard before retrying any request that may have reached Resend.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/jwestburg/skills/resend-send-native-node)\n- [Resend](https://resend.com)\n- [Resend domains](https://resend.com/domains)\n- [Resend pricing](https://resend.com/pricing)\n- [Resend emails API endpoint](https://api.resend.com/emails)\n\n## Skill Output:\n\n**Output Type(s):** [Text, JSON, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Plain text or JSON receipts, with Markdown usage guidance and command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Dry-run receipts include payload details, body byte count, body SHA-256 values, and allowlist status; successful sends include the Resend message ID.]\n\n## Skill Version(s):\n\n1.0.20 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.15: 5 files, 11243 bytes\n\nFiles: scripts/send.mjs (9422b), skill-card.md (2446b), SKILL.md (12492b), tests/run-resend-send-tests.mjs (4459b), _meta.json (143b)\n\nFile v1.0.15:SKILL.md\n\n---\nname: resend-send-native-node\ndescription: Send email via Resend.com's HTTPS API - native Node.js, zero dependencies. Use when the user explicitly asks to email, send a message, mail a report, or deliver a notification to an email address. Externally sends email only with --send; defaults to dry-run and requires RESEND_ALLOWED_TO allowlist for real sends. Requires RESEND_API_KEY in the process environment for real sends. No OAuth, no 2FA, no Gmail required.\nversion: 1.0.15\nrisk_class: external-email-send-dry-run-default-send-gated\n---\n\n# Resend Send Native Node\n\nSend email via the Resend.com HTTPS API.\n\nNative Node.js. Zero dependencies. One POST call for real sends. Small enough to audit directly.\n\n## When to use\n\nTrigger phrases: \"email me\", \"send an email\", \"mail this to\", \"send a notification\", \"email the report\".\n\n**Use this when:**\n- The user wants to send an email fast, without Gmail OAuth or App Password pain\n- Simple \"fire and forget\" sends (no inbox reading needed)\n- The user has a Resend.com account (check Resend's current pricing/limits before relying on a specific quota)\n- Weekly/report-style outbound messages where the body is generated from explicitly reviewed text\n\n**Do NOT use this when:**\n- The user wants to READ email (this is send-only)\n- The user needs to send from a specific personal Gmail address (use a Gmail-specific skill)\n- Sensitive business emails where provenance matters (Resend's default `onboarding@resend.dev` sender looks transactional)\n- The recipient, sender, or final body has not been explicitly reviewed/approved for a real send\n\n## Safety policy for agents\n\nThis skill is send-only, but it is still externally mutating. For agent use:\n\n1. **Draft first.** Generate or inspect the exact body text before sending.\n2. **Dry-run first.** The script dry-runs by default; review the printed payload.\n3. **Explicit approval.** Use `--send` only after the user explicitly approves the exact `to`, `cc`, `bcc`, `from`, `reply-to`, `subject`, and body. Treat `reply-to` as response-routing control and review display-name text in `from` for spoof-like wording before any real send.\n4. **Use an allowlist.** Real sends fail closed unless `RESEND_ALLOWED_TO=addr@example.com,other@example.com` is set in the process environment for approved recipients.\n5. **No raw memory dumps.** Email only curated report text, not unfiltered memory, transcripts, logs, or private workspace context.\n\n## How to run\n\nThe script is in `scripts/send.mjs`. Requires Node.js 18+ because real sends use native `fetch` and `AbortController`.\n\nFor operator workflows, prefer `--json` so dry-runs and real sends produce a stable machine-readable receipt with `mode`, `sent`, recipients, subject, body byte count, full body SHA-256, SHA-256 prefix, allowlist status, and `resendId` on successful real sends.\n\n**Basic:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n```\n\nWithout `--send`, this prints a dry-run payload and does **not** send. Dry-run output includes the full reviewed body JSON plus body byte length and SHA-256 prefix; redact dry-run logs before sharing externally.\n\n**With from address override:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --from \"Example Sender <onboarding@resend.dev>\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi\"\n```\n\n**HTML body:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --html --to \"you@example.com\" --subject \"Styled\" --body \"<h1>Hi</h1><p>Hello</p>\"\n```\n\n**Dry run (no send, just print the payload):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --dry-run --to \"you@example.com\" --subject \"Test\" --body \"...\"\n```\n\nIf `--dry-run` and `--send` are both present, dry-run wins and no email is sent.\n\n**Real send (only after explicit approval):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --send --to \"you@example.com\" --subject \"Weekly report\" --body \"Approved report text\"\n```\n\n### All flags\n\n| Flag | Required? | Purpose |\n|---|---|---|\n| `--to` | yes | Comma-separated recipient addresses |\n| `--subject` | yes | Message subject |\n| `--body` | yes | Inline message body |\n| `--cc` | no | Comma-separated cc |\n| `--bcc` | no | Comma-separated bcc |\n| `--from` | no | Override sender, e.g. `\"Example Sender <onboarding@resend.dev>\"` |\n| `--reply-to` | no | Reply-to address |\n| `--html` | no | Body is HTML instead of plain text |\n| `--dry-run` | no | Don't send; print the JSON payload |\n| `--send` | no | Actually send. Without this, the script dry-runs by default |\n| `--json` | no | Print a stable JSON receipt for dry-run or real send |\n| `-h`, `--help` | no | Show help |\n\nRecipients in `--to`, `--cc`, `--bcc`, and `--reply-to` must be bare email addresses. Only `--from` accepts display-name format such as `\"Reports <reports@example.com>\"`.\n\n`--body-file` is intentionally not supported in the public package. Review file contents yourself and pass approved text with `--body`.\n\n## Credentials\n\nRequires process environment values:\n\n- `RESEND_API_KEY` - starts with `re_...`\n- `RESEND_ALLOWED_TO` - comma-separated recipient allowlist for real sends\n- Real sends require `RESEND_ALLOWED_TO`; without it the script refuses `--send`\n\n**How to get one:**\n1. Sign up at https://resend.com and check the current pricing/limits for the account\n2. Go to **API Keys** in the dashboard\n3. Click **Create API Key**, name it, and choose the least-privilege sending permission available for your account\n4. Copy the key\n\nExport it in the runtime process environment:\n```powershell\n$env:RESEND_API_KEY=\"<your-resend-key>\"\n$env:RESEND_ALLOWED_TO=\"you@example.com,reports@example.com\"\n```\n\n## Sender identity\n\nBy default, emails are sent from `onboarding@resend.dev` - Resend's default sender. This may support quick testing subject to current Resend account restrictions; use a verified domain/sender for production-style mail.\n\n**For a custom domain (later, optional):**\n1. Add your domain to Resend at https://resend.com/domains\n2. Configure DNS records they provide\n3. Use a verified sender with `--from \"Reports <reports@your-verified-domain.example>\"`\n\n## What this skill does\n\n- Reads `RESEND_API_KEY` from the process environment only\n- POSTs a JSON request to `https://api.resend.com/emails`\n- Prints a one-line confirmation with the Resend message ID\n- Defaults to dry-run unless `--send` is present\n- Validates basic recipient address shape before sending\n- Enforces `RESEND_ALLOWED_TO` for real sends; fail-closed if it is missing\n- Prints body byte length and SHA-256 prefix in dry-run so reviewed content can be matched to the send\n- Supports `--json` receipt output so automation can compare the reviewed body hash to the send receipt and capture `resendId` without scraping human text\n\n## What this skill does NOT do\n\n- Does not read or manage email (this is send-only)\n- Does not read local files or support `--body-file`\n- Does not write any files\n- Does not make network calls other than to `api.resend.com`\n- Does not auto-update\n- Does not support attachments in this version\n\n## Output\n\nOn success:\n```\nsent to you@example.com (subject: Hello) - resend-id: c8f43f2a-...\n```\n\nWith `--json`, dry-runs and sends emit parseable JSON. Successful real sends include `sent: true`, `bodySha256`, `bodySha256Prefix`, and `resendId`.\n\nOn failure, clear error on stderr with a non-zero exit code.\n\n## Troubleshooting\n\n- **\"RESEND_API_KEY not set\"** - create one at https://resend.com, check current pricing/limits, and export `RESEND_API_KEY` in the process environment\n- **HTTP 401** - API key is invalid or was revoked\n- **HTTP 403** - API key doesn't have send permission, or the from address can only send to the account owner until a domain is verified (check dashboard). On Windows, a Node.js cleanup assertion may appear after a 403 exit; this is cosmetic and does not indicate a successful send.\n- **HTTP 422** - the from address isn't verified on your Resend account (use `onboarding@resend.dev` or verify your own domain)\n- **HTTP 429** - rate limited; check https://resend.com/pricing or the Resend dashboard for current limits\n- **Network error or timeout** - transient, but a network/timeout/read error after the request was sent does not prove the email was not delivered. Check the Resend dashboard before retrying to avoid duplicate sends.\n\n## Sample output\n\nSanitized representative output for eval/review checks:\n\n```text\n$ node scripts/send.mjs --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n--- DRY RUN: request would be sent ---\nnote: add --send to perform a real send after explicit approval.\nbody: 8 bytes, sha256:8328c36d18b7\nWARNING: RESEND_ALLOWED_TO is not configured. Real sends will fail closed until an allowlist is set.\nPOST https://api.resend.com/emails\nAuthorization: Bearer [redacted]\n\n{\n  \"from\": \"onboarding@resend.dev\",\n  \"to\": [\n    \"you@example.com\"\n  ],\n  \"subject\": \"Hello\",\n  \"text\": \"Hi there\"\n}\n\n$ node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\nerror: RESEND_ALLOWED_TO must be set for real sends. Refusing --send without a recipient allowlist.\n\n# PowerShell:\n$env:RESEND_ALLOWED_TO=\"you@example.com\"; node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n# bash/zsh:\n# RESEND_ALLOWED_TO=\"you@example.com\" node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\nerror: RESEND_API_KEY not set in process environment. Create one at https://resend.com, check current pricing/limits, and export RESEND_API_KEY.\n```\n\n## Required checks before publishing/updating\n\nMinimum no-send checks:\n\n```powershell\nnode --check skills\\resend-send-native-node\\scripts\\send.mjs\nnode skills\\resend-send-native-node\\scripts\\send.mjs --help\nnode skills\\resend-send-native-node\\scripts\\send.mjs --to \"test@example.com\" --subject \"Smoke\" --body \"Hello\" --json\nnode skills\\resend-send-native-node\\tests\\run-resend-send-tests.mjs\n```\n\nThe smoke command above must remain a dry-run: do not include `--send`. Real sends require separate explicit approval for the exact recipient headers, subject, and body plus an allowlist.\n\n## Account limits\n\nResend pricing and free-tier limits can change. Check the current Resend dashboard/pricing page before relying on a specific daily/monthly quota or paid-tier price. New accounts commonly support quick testing from `onboarding@resend.dev`; use a verified domain/sender for production-style mail.\n\n## Changelog\n\n- `1.0.15`: Document the actual no-send publish/update checks, including the existing `tests\\run-resend-send-tests.mjs` runner, so public update gates do not rely on a nonexistent self-test path. No send behavior change.\n- `1.0.14`: Public package eval hygiene: generate the Resend API-key-shaped test sentinel at runtime so package scanners do not see a static key-shaped string in source; no send behavior change.\n- `1.0.13`: Source-polish retest prep: genericized a review fixture subject, documented that `--dry-run --send` resolves to dry-run, and normalized SKILL.md line endings; no send behavior change.\n- `1.0.12`: ClawHub publication/version refresh after JSON receipt fix and public-readiness review; no additional runtime behavior change.\n- `1.0.11`: Add `--json` structured receipts for dry-run and real send output so operators can capture stable subjects, body hashes, allowlist status, and `resendId` without scraping human text.\n- `1.0.10`: Clarify explicit approval must cover all delivery/reply headers (`to`, `cc`, `bcc`, `from`, `reply-to`), subject, and body before real sends.\n- `1.0.9`: Add explicit Node.js 18+ usage prerequisite and offline gate-regression tests for dry-run, allowlist fail-closed, missing-key fail-closed, HTML/reply-to payloads, unsupported body-file, invalid recipients, and help output.\n- `1.0.8`: Soften public Resend account/default-sender wording to avoid stale pricing/free-tier/domain-setup assumptions.\n- `1.0.7`: Fix no-allowlist sample output, document bare-recipient requirement and dry-run body visibility, add 30s send timeout, and warn to verify Resend dashboard before retrying ambiguous network/timeout failures.\n- `1.0.6`: Add frontmatter version metadata, hedge rate-limit wording, document Windows 403 cleanup assertion behavior, and include sanitized dry-run/fail-closed sample outputs for eval review.\n- `1.0.5`: Public package wording and metadata cleanup; send behavior remains dry-run-first with `--send` plus recipient allowlist required for real sends.\n\nFile v1.0.15:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"resend-send-native-node\",\n  \"version\": \"1.0.15\",\n  \"publishedAt\": 1784147976188\n}\n\nFile v1.0.15:skill-card.md\n\n## Description: <br>\nSends email through Resend's HTTPS API with a zero-dependency Node.js script that defaults to dry-run and requires explicit send flags, an API key, and a recipient allowlist for real email. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jwestburg](https://clawhub.ai/user/jwestburg) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and operators use this skill to draft, review, dry-run, and, after explicit approval, send outbound email through a Resend account from Node.js without OAuth or dependencies. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can send real external email when explicitly invoked with credentials. <br>\nMitigation: Keep the default dry-run flow, require exact user approval before adding --send, and enforce RESEND_ALLOWED_TO for all real recipients. <br>\nRisk: Dry-run logs include the full message body and may expose sensitive reviewed content if shared. <br>\nMitigation: Review dry-run output locally, avoid sending raw transcripts or private workspace context, and redact dry-run logs before sharing them. <br>\nRisk: A timeout or network error after a send attempt may leave delivery status ambiguous. <br>\nMitigation: Check the Resend dashboard before retrying to avoid duplicate messages. <br>\n\n\n## Reference(s): <br>\n- [Resend](https://resend.com) <br>\n- [Resend Domains](https://resend.com/domains) <br>\n- [Resend Pricing](https://resend.com/pricing) <br>\n- [ClawHub skill page](https://clawhub.ai/jwestburg/skills/resend-send-native-node) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Shell commands, Configuration, Text, JSON] <br>\n**Output Format:** [Markdown guidance with inline shell commands; the script emits plain-text status messages or JSON receipts.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Dry-runs include the reviewed message payload, body byte count, and SHA-256 body hash; successful real sends include a Resend message ID.] <br>\n\n## Skill Version(s): <br>\n1.0.15 (source: frontmatter and server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.12: 5 files, 10838 bytes\n\nFiles: scripts/send.mjs (9422b), skill-card.md (2539b), SKILL.md (11216b), tests/run-resend-send-tests.mjs (4379b), _meta.json (143b)\n\nFile v1.0.12:SKILL.md\n\n---\nname: resend-send-native-node\ndescription: Send email via Resend.com's HTTPS API - native Node.js, zero dependencies. Use when the user explicitly asks to email, send a message, mail a report, or deliver a notification to an email address. Externally sends email only with --send; defaults to dry-run and requires RESEND_ALLOWED_TO allowlist for real sends. Requires RESEND_API_KEY in the process environment for real sends. No OAuth, no 2FA, no Gmail required.\nversion: 1.0.12\nrisk_class: external-email-send-dry-run-default-send-gated\n---\n\n# Resend Send Native Node\n\nSend email via the Resend.com HTTPS API.\n\nNative Node.js. Zero dependencies. One POST call for real sends. Small enough to audit directly.\n\n## When to use\n\nTrigger phrases: \"email me\", \"send an email\", \"mail this to\", \"send a notification\", \"email the report\".\n\n**Use this when:**\n- The user wants to send an email fast, without Gmail OAuth or App Password pain\n- Simple \"fire and forget\" sends (no inbox reading needed)\n- The user has a Resend.com account (check Resend's current pricing/limits before relying on a specific quota)\n- Weekly/report-style outbound messages where the body is generated from explicitly reviewed text\n\n**Do NOT use this when:**\n- The user wants to READ email (this is send-only)\n- The user needs to send from a specific personal Gmail address (use a Gmail-specific skill)\n- Sensitive business emails where provenance matters (Resend's default `onboarding@resend.dev` sender looks transactional)\n- The recipient, sender, or final body has not been explicitly reviewed/approved for a real send\n\n## Safety policy for agents\n\nThis skill is send-only, but it is still externally mutating. For agent use:\n\n1. **Draft first.** Generate or inspect the exact body text before sending.\n2. **Dry-run first.** The script dry-runs by default; review the printed payload.\n3. **Explicit approval.** Use `--send` only after the user explicitly approves the exact `to`, `cc`, `bcc`, `from`, `reply-to`, `subject`, and body. Treat `reply-to` as response-routing control and review display-name text in `from` for spoof-like wording before any real send.\n4. **Use an allowlist.** Real sends fail closed unless `RESEND_ALLOWED_TO=addr@example.com,other@example.com` is set in the process environment for approved recipients.\n5. **No raw memory dumps.** Email only curated report text, not unfiltered memory, transcripts, logs, or private workspace context.\n\n## How to run\n\nThe script is in `scripts/send.mjs`. Requires Node.js 18+ because real sends use native `fetch` and `AbortController`.\n\nFor operator workflows, prefer `--json` so dry-runs and real sends produce a stable machine-readable receipt with `mode`, `sent`, recipients, subject, body byte count, full body SHA-256, SHA-256 prefix, allowlist status, and `resendId` on successful real sends.\n\n**Basic:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n```\n\nWithout `--send`, this prints a dry-run payload and does **not** send. Dry-run output includes the full reviewed body JSON plus body byte length and SHA-256 prefix; redact dry-run logs before sharing externally.\n\n**With from address override:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --from \"Example Sender <onboarding@resend.dev>\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi\"\n```\n\n**HTML body:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --html --to \"you@example.com\" --subject \"Styled\" --body \"<h1>Hi</h1><p>Hello</p>\"\n```\n\n**Dry run (no send, just print the payload):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --dry-run --to \"you@example.com\" --subject \"Test\" --body \"...\"\n```\n\n**Real send (only after explicit approval):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --send --to \"you@example.com\" --subject \"Weekly report\" --body \"Approved report text\"\n```\n\n### All flags\n\n| Flag | Required? | Purpose |\n|---|---|---|\n| `--to` | yes | Comma-separated recipient addresses |\n| `--subject` | yes | Message subject |\n| `--body` | yes | Inline message body |\n| `--cc` | no | Comma-separated cc |\n| `--bcc` | no | Comma-separated bcc |\n| `--from` | no | Override sender, e.g. `\"Example Sender <onboarding@resend.dev>\"` |\n| `--reply-to` | no | Reply-to address |\n| `--html` | no | Body is HTML instead of plain text |\n| `--dry-run` | no | Don't send; print the JSON payload |\n| `--send` | no | Actually send. Without this, the script dry-runs by default |\n| `--json` | no | Print a stable JSON receipt for dry-run or real send |\n| `-h`, `--help` | no | Show help |\n\nRecipients in `--to`, `--cc`, `--bcc`, and `--reply-to` must be bare email addresses. Only `--from` accepts display-name format such as `\"Reports <reports@example.com>\"`.\n\n`--body-file` is intentionally not supported in the public package. Review file contents yourself and pass approved text with `--body`.\n\n## Credentials\n\nRequires process environment values:\n\n- `RESEND_API_KEY` - starts with `re_...`\n- `RESEND_ALLOWED_TO` - comma-separated recipient allowlist for real sends\n- Real sends require `RESEND_ALLOWED_TO`; without it the script refuses `--send`\n\n**How to get one:**\n1. Sign up at https://resend.com and check the current pricing/limits for the account\n2. Go to **API Keys** in the dashboard\n3. Click **Create API Key**, name it, and choose the least-privilege sending permission available for your account\n4. Copy the key\n\nExport it in the runtime process environment:\n```powershell\n$env:RESEND_API_KEY=\"<your-resend-key>\"\n$env:RESEND_ALLOWED_TO=\"you@example.com,reports@example.com\"\n```\n\n## Sender identity\n\nBy default, emails are sent from `onboarding@resend.dev` - Resend's default sender. This may support quick testing subject to current Resend account restrictions; use a verified domain/sender for production-style mail.\n\n**For a custom domain (later, optional):**\n1. Add your domain to Resend at https://resend.com/domains\n2. Configure DNS records they provide\n3. Use a verified sender with `--from \"Reports <reports@your-verified-domain.example>\"`\n\n## What this skill does\n\n- Reads `RESEND_API_KEY` from the process environment only\n- POSTs a JSON request to `https://api.resend.com/emails`\n- Prints a one-line confirmation with the Resend message ID\n- Defaults to dry-run unless `--send` is present\n- Validates basic recipient address shape before sending\n- Enforces `RESEND_ALLOWED_TO` for real sends; fail-closed if it is missing\n- Prints body byte length and SHA-256 prefix in dry-run so reviewed content can be matched to the send\n- Supports `--json` receipt output so automation can compare the reviewed body hash to the send receipt and capture `resendId` without scraping human text\n\n## What this skill does NOT do\n\n- Does not read or manage email (this is send-only)\n- Does not read local files or support `--body-file`\n- Does not write any files\n- Does not make network calls other than to `api.resend.com`\n- Does not auto-update\n- Does not support attachments in this version\n\n## Output\n\nOn success:\n```\nsent to you@example.com (subject: Hello) - resend-id: c8f43f2a-...\n```\n\nWith `--json`, dry-runs and sends emit parseable JSON. Successful real sends include `sent: true`, `bodySha256`, `bodySha256Prefix`, and `resendId`.\n\nOn failure, clear error on stderr with a non-zero exit code.\n\n## Troubleshooting\n\n- **\"RESEND_API_KEY not set\"** - create one at https://resend.com, check current pricing/limits, and export `RESEND_API_KEY` in the process environment\n- **HTTP 401** - API key is invalid or was revoked\n- **HTTP 403** - API key doesn't have send permission, or the from address can only send to the account owner until a domain is verified (check dashboard). On Windows, a Node.js cleanup assertion may appear after a 403 exit; this is cosmetic and does not indicate a successful send.\n- **HTTP 422** - the from address isn't verified on your Resend account (use `onboarding@resend.dev` or verify your own domain)\n- **HTTP 429** - rate limited; check https://resend.com/pricing or the Resend dashboard for current limits\n- **Network error or timeout** - transient, but a network/timeout/read error after the request was sent does not prove the email was not delivered. Check the Resend dashboard before retrying to avoid duplicate sends.\n\n## Sample output\n\nSanitized representative output for eval/review checks:\n\n```text\n$ node scripts/send.mjs --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n--- DRY RUN: request would be sent ---\nnote: add --send to perform a real send after explicit approval.\nbody: 8 bytes, sha256:8328c36d18b7\nWARNING: RESEND_ALLOWED_TO is not configured. Real sends will fail closed until an allowlist is set.\nPOST https://api.resend.com/emails\nAuthorization: Bearer [redacted]\n\n{\n  \"from\": \"onboarding@resend.dev\",\n  \"to\": [\n    \"you@example.com\"\n  ],\n  \"subject\": \"Hello\",\n  \"text\": \"Hi there\"\n}\n\n$ node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\nerror: RESEND_ALLOWED_TO must be set for real sends. Refusing --send without a recipient allowlist.\n\n# PowerShell:\n$env:RESEND_ALLOWED_TO=\"you@example.com\"; node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n# bash/zsh:\n# RESEND_ALLOWED_TO=\"you@example.com\" node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\nerror: RESEND_API_KEY not set in process environment. Create one at https://resend.com, check current pricing/limits, and export RESEND_API_KEY.\n```\n\n## Account limits\n\nResend pricing and free-tier limits can change. Check the current Resend dashboard/pricing page before relying on a specific daily/monthly quota or paid-tier price. New accounts commonly support quick testing from `onboarding@resend.dev`; use a verified domain/sender for production-style mail.\n\n## Changelog\n\n- `1.0.12`: ClawHub publication/version refresh after JSON receipt fix and public-readiness review; no additional runtime behavior change.\n- `1.0.11`: Add `--json` structured receipts for dry-run and real send output so operators can capture stable subjects, body hashes, allowlist status, and `resendId` without scraping human text.\n- `1.0.10`: Clarify explicit approval must cover all delivery/reply headers (`to`, `cc`, `bcc`, `from`, `reply-to`), subject, and body before real sends.\n- `1.0.9`: Add explicit Node.js 18+ usage prerequisite and offline gate-regression tests for dry-run, allowlist fail-closed, missing-key fail-closed, HTML/reply-to payloads, unsupported body-file, invalid recipients, and help output.\n- `1.0.8`: Soften public Resend account/default-sender wording to avoid stale pricing/free-tier/domain-setup assumptions.\n- `1.0.7`: Fix no-allowlist sample output, document bare-recipient requirement and dry-run body visibility, add 30s send timeout, and warn to verify Resend dashboard before retrying ambiguous network/timeout failures.\n- `1.0.6`: Add frontmatter version metadata, hedge rate-limit wording, document Windows 403 cleanup assertion behavior, and include sanitized dry-run/fail-closed sample outputs for eval review.\n- `1.0.5`: Public package wording and metadata cleanup; send behavior remains dry-run-first with `--send` plus recipient allowlist required for real sends.\n\nFile v1.0.12:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"resend-send-native-node\",\n  \"version\": \"1.0.12\",\n  \"publishedAt\": 1781477021586\n}\n\nFile v1.0.12:skill-card.md\n\n## Description: <br>\nSend email through Resend.com's HTTPS API from native Node.js with dry-run output by default and explicit send gating for real messages. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jwestburg](https://clawhub.ai/user/jwestburg) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and operators use this skill when an agent needs to draft and, after explicit approval, send outbound email through Resend. It is suited for simple notifications and generated report delivery where recipients, headers, subject, and body are reviewed before a real send. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: A real email send can externally disclose unintended content or reach the wrong recipient. <br>\nMitigation: Keep the default dry-run flow, review the exact body and all delivery headers, require explicit approval before adding --send, and keep RESEND_ALLOWED_TO narrow. <br>\nRisk: The runtime needs a Resend API key to send email. <br>\nMitigation: Provide RESEND_API_KEY only through the process environment, prefer a least-privilege key for a verified sender or domain, and avoid sharing dry-run logs that contain reviewed message content. <br>\nRisk: Network timeouts or read errors after a request is sent may leave delivery status ambiguous. <br>\nMitigation: Check the Resend dashboard before retrying to reduce duplicate-send risk. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jwestburg/resend-send-native-node) <br>\n- [Resend](https://resend.com) <br>\n- [Resend domains](https://resend.com/domains) <br>\n- [Resend pricing](https://resend.com/pricing) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Shell commands, JSON, Guidance] <br>\n**Output Format:** [Markdown guidance with shell command examples and optional JSON receipts] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Dry-run and send receipts can include recipient lists, subject, content type, body byte count, body SHA-256 values, allowlist status, and Resend message ID for successful real sends.] <br>\n\n## Skill Version(s): <br>\n1.0.12 (source: evidence release and SKILL.md frontmatter) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.10: 5 files, 9987 bytes\n\nFiles: scripts/send.mjs (8238b), skill-card.md (2685b), SKILL.md (10177b), tests/run-resend-send-tests.mjs (3201b), _meta.json (143b)\n\nFile v1.0.10:SKILL.md\n\n---\nname: resend-send-native-node\ndescription: Send email via Resend.com's HTTPS API - native Node.js, zero dependencies. Use when the user explicitly asks to email, send a message, mail a report, or deliver a notification to an email address. Externally sends email only with --send; defaults to dry-run and requires RESEND_ALLOWED_TO allowlist for real sends. Requires RESEND_API_KEY in the process environment for real sends. No OAuth, no 2FA, no Gmail required.\nversion: 1.0.10\n---\n\n# Resend Send Native Node\n\nSend email via the Resend.com HTTPS API.\n\nNative Node.js. Zero dependencies. One POST call for real sends. Small enough to audit directly.\n\n## When to use\n\nTrigger phrases: \"email me\", \"send an email\", \"mail this to\", \"send a notification\", \"email the report\".\n\n**Use this when:**\n- The user wants to send an email fast, without Gmail OAuth or App Password pain\n- Simple \"fire and forget\" sends (no inbox reading needed)\n- The user has a Resend.com account (check Resend's current pricing/limits before relying on a specific quota)\n- Weekly/report-style outbound messages where the body is generated from explicitly reviewed text\n\n**Do NOT use this when:**\n- The user wants to READ email (this is send-only)\n- The user needs to send from a specific personal Gmail address (use a Gmail-specific skill)\n- Sensitive business emails where provenance matters (Resend's default `onboarding@resend.dev` sender looks transactional)\n- The recipient, sender, or final body has not been explicitly reviewed/approved for a real send\n\n## Safety policy for agents\n\nThis skill is send-only, but it is still externally mutating. For agent use:\n\n1. **Draft first.** Generate or inspect the exact body text before sending.\n2. **Dry-run first.** The script dry-runs by default; review the printed payload.\n3. **Explicit approval.** Use `--send` only after the user explicitly approves the exact `to`, `cc`, `bcc`, `from`, `reply-to`, `subject`, and body. Treat `reply-to` as response-routing control and review display-name text in `from` for spoof-like wording before any real send.\n4. **Use an allowlist.** Real sends fail closed unless `RESEND_ALLOWED_TO=addr@example.com,other@example.com` is set in the process environment for approved recipients.\n5. **No raw memory dumps.** Email only curated report text, not unfiltered memory, transcripts, logs, or private workspace context.\n\n## How to run\n\nThe script is in `scripts/send.mjs`. Requires Node.js 18+ because real sends use native `fetch` and `AbortController`.\n\n**Basic:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n```\n\nWithout `--send`, this prints a dry-run payload and does **not** send. Dry-run output includes the full reviewed body JSON plus body byte length and SHA-256 prefix; redact dry-run logs before sharing externally.\n\n**With from address override:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --from \"Example Sender <onboarding@resend.dev>\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi\"\n```\n\n**HTML body:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --html --to \"you@example.com\" --subject \"Styled\" --body \"<h1>Hi</h1><p>Hello</p>\"\n```\n\n**Dry run (no send, just print the payload):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --dry-run --to \"you@example.com\" --subject \"Test\" --body \"...\"\n```\n\n**Real send (only after explicit approval):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --send --to \"you@example.com\" --subject \"Weekly report\" --body \"Approved report text\"\n```\n\n### All flags\n\n| Flag | Required? | Purpose |\n|---|---|---|\n| `--to` | yes | Comma-separated recipient addresses |\n| `--subject` | yes | Message subject |\n| `--body` | yes | Inline message body |\n| `--cc` | no | Comma-separated cc |\n| `--bcc` | no | Comma-separated bcc |\n| `--from` | no | Override sender, e.g. `\"Example Sender <onboarding@resend.dev>\"` |\n| `--reply-to` | no | Reply-to address |\n| `--html` | no | Body is HTML instead of plain text |\n| `--dry-run` | no | Don't send; print the JSON payload |\n| `--send` | no | Actually send. Without this, the script dry-runs by default |\n| `-h`, `--help` | no | Show help |\n\nRecipients in `--to`, `--cc`, `--bcc`, and `--reply-to` must be bare email addresses. Only `--from` accepts display-name format such as `\"Reports <reports@example.com>\"`.\n\n`--body-file` is intentionally not supported in the public package. Review file contents yourself and pass approved text with `--body`.\n\n## Credentials\n\nRequires process environment values:\n\n- `RESEND_API_KEY` - starts with `re_...`\n- `RESEND_ALLOWED_TO` - comma-separated recipient allowlist for real sends\n- Real sends require `RESEND_ALLOWED_TO`; without it the script refuses `--send`\n\n**How to get one:**\n1. Sign up at https://resend.com and check the current pricing/limits for the account\n2. Go to **API Keys** in the dashboard\n3. Click **Create API Key**, name it, and choose the least-privilege sending permission available for your account\n4. Copy the key\n\nExport it in the runtime process environment:\n```powershell\n$env:RESEND_API_KEY=\"<your-resend-key>\"\n$env:RESEND_ALLOWED_TO=\"you@example.com,reports@example.com\"\n```\n\n## Sender identity\n\nBy default, emails are sent from `onboarding@resend.dev` - Resend's default sender. This may support quick testing subject to current Resend account restrictions; use a verified domain/sender for production-style mail.\n\n**For a custom domain (later, optional):**\n1. Add your domain to Resend at https://resend.com/domains\n2. Configure DNS records they provide\n3. Use a verified sender with `--from \"Reports <reports@your-verified-domain.example>\"`\n\n## What this skill does\n\n- Reads `RESEND_API_KEY` from the process environment only\n- POSTs a JSON request to `https://api.resend.com/emails`\n- Prints a one-line confirmation with the Resend message ID\n- Defaults to dry-run unless `--send` is present\n- Validates basic recipient address shape before sending\n- Enforces `RESEND_ALLOWED_TO` for real sends; fail-closed if it is missing\n- Prints body byte length and SHA-256 prefix in dry-run so reviewed content can be matched to the send\n\n## What this skill does NOT do\n\n- Does not read or manage email (this is send-only)\n- Does not read local files or support `--body-file`\n- Does not write any files\n- Does not make network calls other than to `api.resend.com`\n- Does not auto-update\n- Does not support attachments in this version\n\n## Output\n\nOn success:\n```\nsent to you@example.com (subject: Hello) - resend-id: c8f43f2a-...\n```\n\nOn failure, clear error on stderr with a non-zero exit code.\n\n## Troubleshooting\n\n- **\"RESEND_API_KEY not set\"** - create one at https://resend.com, check current pricing/limits, and export `RESEND_API_KEY` in the process environment\n- **HTTP 401** - API key is invalid or was revoked\n- **HTTP 403** - API key doesn't have send permission, or the from address can only send to the account owner until a domain is verified (check dashboard). On Windows, a Node.js cleanup assertion may appear after a 403 exit; this is cosmetic and does not indicate a successful send.\n- **HTTP 422** - the from address isn't verified on your Resend account (use `onboarding@resend.dev` or verify your own domain)\n- **HTTP 429** - rate limited; check https://resend.com/pricing or the Resend dashboard for current limits\n- **Network error or timeout** - transient, but a network/timeout/read error after the request was sent does not prove the email was not delivered. Check the Resend dashboard before retrying to avoid duplicate sends.\n\n## Sample output\n\nSanitized representative output for eval/review checks:\n\n```text\n$ node scripts/send.mjs --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n--- DRY RUN: request would be sent ---\nnote: add --send to perform a real send after explicit approval.\nbody: 8 bytes, sha256:8328c36d18b7\nWARNING: RESEND_ALLOWED_TO is not configured. Real sends will fail closed until an allowlist is set.\nPOST https://api.resend.com/emails\nAuthorization: Bearer [redacted]\n\n{\n  \"from\": \"onboarding@resend.dev\",\n  \"to\": [\n    \"you@example.com\"\n  ],\n  \"subject\": \"Hello\",\n  \"text\": \"Hi there\"\n}\n\n$ node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\nerror: RESEND_ALLOWED_TO must be set for real sends. Refusing --send without a recipient allowlist.\n\n# PowerShell:\n$env:RESEND_ALLOWED_TO=\"you@example.com\"; node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n# bash/zsh:\n# RESEND_ALLOWED_TO=\"you@example.com\" node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\nerror: RESEND_API_KEY not set in process environment. Create one at https://resend.com, check current pricing/limits, and export RESEND_API_KEY.\n```\n\n## Account limits\n\nResend pricing and free-tier limits can change. Check the current Resend dashboard/pricing page before relying on a specific daily/monthly quota or paid-tier price. New accounts commonly support quick testing from `onboarding@resend.dev`; use a verified domain/sender for production-style mail.\n\n## Changelog\n\n- `1.0.10`: Clarify explicit approval must cover all delivery/reply headers (`to`, `cc`, `bcc`, `from`, `reply-to`), subject, and body before real sends.\n- `1.0.9`: Add explicit Node.js 18+ usage prerequisite and offline gate-regression tests for dry-run, allowlist fail-closed, missing-key fail-closed, HTML/reply-to payloads, unsupported body-file, invalid recipients, and help output.\n- `1.0.8`: Soften public Resend account/default-sender wording to avoid stale pricing/free-tier/domain-setup assumptions.\n- `1.0.7`: Fix no-allowlist sample output, document bare-recipient requirement and dry-run body visibility, add 30s send timeout, and warn to verify Resend dashboard before retrying ambiguous network/timeout failures.\n- `1.0.6`: Add frontmatter version metadata, hedge rate-limit wording, document Windows 403 cleanup assertion behavior, and include sanitized dry-run/fail-closed sample outputs for eval review.\n- `1.0.5`: Public package wording and metadata cleanup; send behavior remains dry-run-first with `--send` plus recipient allowlist required for real sends.\n\nFile v1.0.10:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"resend-send-native-node\",\n  \"version\": \"1.0.10\",\n  \"publishedAt\": 1781272432660\n}\n\nFile v1.0.10:skill-card.md\n\n## Description: <br>\nSend email through Resend.com's HTTPS API using native Node.js, defaulting to dry-run and requiring explicit --send, RESEND_API_KEY, and an allowed-recipient list for real sends. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jwestburg](https://clawhub.ai/user/jwestburg) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and operators use this skill to let an agent draft and send explicitly approved outbound emails through a Resend account, such as notifications or reviewed reports. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can send outbound email through a user's Resend account when --send is used. <br>\nMitigation: Keep the default dry-run flow, review the printed payload, and require explicit approval of to, cc, bcc, from, reply-to, subject, and body before any real send. <br>\nRisk: A broad recipient set could send messages to unintended addresses. <br>\nMitigation: Keep RESEND_ALLOWED_TO narrow and treat the allowlist as the boundary for approved real-send recipients. <br>\nRisk: Email bodies or dry-run logs may expose private workspace context, transcripts, or raw logs. <br>\nMitigation: Send only curated report text and redact dry-run logs before sharing them outside the trusted workspace. <br>\nRisk: A network timeout or read error after submission may leave delivery status ambiguous and cause duplicate emails on retry. <br>\nMitigation: Check the Resend dashboard before retrying a failed or timed-out send. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jwestburg/resend-send-native-node) <br>\n- [Resend](https://resend.com) <br>\n- [Resend domains](https://resend.com/domains) <br>\n- [Resend pricing](https://resend.com/pricing) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with inline shell commands, JSON dry-run payloads, and one-line send confirmations or stderr errors from the script.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Dry-run output includes the reviewed body JSON, byte length, SHA-256 prefix, target endpoint, and a redacted Authorization header.] <br>\n\n## Skill Version(s): <br>\n1.0.10 (source: frontmatter and server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.9: 5 files, 9824 bytes\n\nFiles: scripts/send.mjs (8238b), skill-card.md (2664b), SKILL.md (9864b), tests/run-resend-send-tests.mjs (3201b), _meta.json (142b)\n\nFile v1.0.9:SKILL.md\n\n---\nname: resend-send-native-node\ndescription: Send email via Resend.com's HTTPS API - native Node.js, zero dependencies. Use when the user explicitly asks to email, send a message, mail a report, or deliver a notification to an email address. Externally sends email only with --send; defaults to dry-run and requires RESEND_ALLOWED_TO allowlist for real sends. Requires RESEND_API_KEY in the process environment for real sends. No OAuth, no 2FA, no Gmail required.\nversion: 1.0.9\n---\n\n# Resend Send Native Node\n\nSend email via the Resend.com HTTPS API.\n\nNative Node.js. Zero dependencies. One POST call for real sends. Small enough to audit directly.\n\n## When to use\n\nTrigger phrases: \"email me\", \"send an email\", \"mail this to\", \"send a notification\", \"email the report\".\n\n**Use this when:**\n- The user wants to send an email fast, without Gmail OAuth or App Password pain\n- Simple \"fire and forget\" sends (no inbox reading needed)\n- The user has a Resend.com account (check Resend's current pricing/limits before relying on a specific quota)\n- Weekly/report-style outbound messages where the body is generated from explicitly reviewed text\n\n**Do NOT use this when:**\n- The user wants to READ email (this is send-only)\n- The user needs to send from a specific personal Gmail address (use a Gmail-specific skill)\n- Sensitive business emails where provenance matters (Resend's default `onboarding@resend.dev` sender looks transactional)\n- The recipient, sender, or final body has not been explicitly reviewed/approved for a real send\n\n## Safety policy for agents\n\nThis skill is send-only, but it is still externally mutating. For agent use:\n\n1. **Draft first.** Generate or inspect the exact body text before sending.\n2. **Dry-run first.** The script dry-runs by default; review the printed payload.\n3. **Explicit approval.** Use `--send` only after the user explicitly approves that exact recipient, subject, and body.\n4. **Use an allowlist.** Real sends fail closed unless `RESEND_ALLOWED_TO=addr@example.com,other@example.com` is set in the process environment for approved recipients.\n5. **No raw memory dumps.** Email only curated report text, not unfiltered memory, transcripts, logs, or private workspace context.\n\n## How to run\n\nThe script is in `scripts/send.mjs`. Requires Node.js 18+ because real sends use native `fetch` and `AbortController`.\n\n**Basic:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n```\n\nWithout `--send`, this prints a dry-run payload and does **not** send. Dry-run output includes the full reviewed body JSON plus body byte length and SHA-256 prefix; redact dry-run logs before sharing externally.\n\n**With from address override:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --from \"Example Sender <onboarding@resend.dev>\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi\"\n```\n\n**HTML body:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --html --to \"you@example.com\" --subject \"Styled\" --body \"<h1>Hi</h1><p>Hello</p>\"\n```\n\n**Dry run (no send, just print the payload):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --dry-run --to \"you@example.com\" --subject \"Test\" --body \"...\"\n```\n\n**Real send (only after explicit approval):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --send --to \"you@example.com\" --subject \"Weekly report\" --body \"Approved report text\"\n```\n\n### All flags\n\n| Flag | Required? | Purpose |\n|---|---|---|\n| `--to` | yes | Comma-separated recipient addresses |\n| `--subject` | yes | Message subject |\n| `--body` | yes | Inline message body |\n| `--cc` | no | Comma-separated cc |\n| `--bcc` | no | Comma-separated bcc |\n| `--from` | no | Override sender, e.g. `\"Example Sender <onboarding@resend.dev>\"` |\n| `--reply-to` | no | Reply-to address |\n| `--html` | no | Body is HTML instead of plain text |\n| `--dry-run` | no | Don't send; print the JSON payload |\n| `--send` | no | Actually send. Without this, the script dry-runs by default |\n| `-h`, `--help` | no | Show help |\n\nRecipients in `--to`, `--cc`, `--bcc`, and `--reply-to` must be bare email addresses. Only `--from` accepts display-name format such as `\"Reports <reports@example.com>\"`.\n\n`--body-file` is intentionally not supported in the public package. Review file contents yourself and pass approved text with `--body`.\n\n## Credentials\n\nRequires process environment values:\n\n- `RESEND_API_KEY` - starts with `re_...`\n- `RESEND_ALLOWED_TO` - comma-separated recipient allowlist for real sends\n- Real sends require `RESEND_ALLOWED_TO`; without it the script refuses `--send`\n\n**How to get one:**\n1. Sign up at https://resend.com and check the current pricing/limits for the account\n2. Go to **API Keys** in the dashboard\n3. Click **Create API Key**, name it, and choose the least-privilege sending permission available for your account\n4. Copy the key\n\nExport it in the runtime process environment:\n```powershell\n$env:RESEND_API_KEY=\"<your-resend-key>\"\n$env:RESEND_ALLOWED_TO=\"you@example.com,reports@example.com\"\n```\n\n## Sender identity\n\nBy default, emails are sent from `onboarding@resend.dev` - Resend's default sender. This may support quick testing subject to current Resend account restrictions; use a verified domain/sender for production-style mail.\n\n**For a custom domain (later, optional):**\n1. Add your domain to Resend at https://resend.com/domains\n2. Configure DNS records they provide\n3. Use a verified sender with `--from \"Reports <reports@your-verified-domain.example>\"`\n\n## What this skill does\n\n- Reads `RESEND_API_KEY` from the process environment only\n- POSTs a JSON request to `https://api.resend.com/emails`\n- Prints a one-line confirmation with the Resend message ID\n- Defaults to dry-run unless `--send` is present\n- Validates basic recipient address shape before sending\n- Enforces `RESEND_ALLOWED_TO` for real sends; fail-closed if it is missing\n- Prints body byte length and SHA-256 prefix in dry-run so reviewed content can be matched to the send\n\n## What this skill does NOT do\n\n- Does not read or manage email (this is send-only)\n- Does not read local files or support `--body-file`\n- Does not write any files\n- Does not make network calls other than to `api.resend.com`\n- Does not auto-update\n- Does not support attachments in this version\n\n## Output\n\nOn success:\n```\nsent to you@example.com (subject: Hello) - resend-id: c8f43f2a-...\n```\n\nOn failure, clear error on stderr with a non-zero exit code.\n\n## Troubleshooting\n\n- **\"RESEND_API_KEY not set\"** - create one at https://resend.com, check current pricing/limits, and export `RESEND_API_KEY` in the process environment\n- **HTTP 401** - API key is invalid or was revoked\n- **HTTP 403** - API key doesn't have send permission, or the from address can only send to the account owner until a domain is verified (check dashboard). On Windows, a Node.js cleanup assertion may appear after a 403 exit; this is cosmetic and does not indicate a successful send.\n- **HTTP 422** - the from address isn't verified on your Resend account (use `onboarding@resend.dev` or verify your own domain)\n- **HTTP 429** - rate limited; check https://resend.com/pricing or the Resend dashboard for current limits\n- **Network error or timeout** - transient, but a network/timeout/read error after the request was sent does not prove the email was not delivered. Check the Resend dashboard before retrying to avoid duplicate sends.\n\n## Sample output\n\nSanitized representative output for eval/review checks:\n\n```text\n$ node scripts/send.mjs --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n--- DRY RUN: request would be sent ---\nnote: add --send to perform a real send after explicit approval.\nbody: 8 bytes, sha256:8328c36d18b7\nWARNING: RESEND_ALLOWED_TO is not configured. Real sends will fail closed until an allowlist is set.\nPOST https://api.resend.com/emails\nAuthorization: Bearer [redacted]\n\n{\n  \"from\": \"onboarding@resend.dev\",\n  \"to\": [\n    \"you@example.com\"\n  ],\n  \"subject\": \"Hello\",\n  \"text\": \"Hi there\"\n}\n\n$ node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\nerror: RESEND_ALLOWED_TO must be set for real sends. Refusing --send without a recipient allowlist.\n\n# PowerShell:\n$env:RESEND_ALLOWED_TO=\"you@example.com\"; node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n# bash/zsh:\n# RESEND_ALLOWED_TO=\"you@example.com\" node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\nerror: RESEND_API_KEY not set in process environment. Create one at https://resend.com, check current pricing/limits, and export RESEND_API_KEY.\n```\n\n## Account limits\n\nResend pricing and free-tier limits can change. Check the current Resend dashboard/pricing page before relying on a specific daily/monthly quota or paid-tier price. New accounts commonly support quick testing from `onboarding@resend.dev`; use a verified domain/sender for production-style mail.\n\n## Changelog\n\n- `1.0.9`: Add explicit Node.js 18+ usage prerequisite and offline gate-regression tests for dry-run, allowlist fail-closed, missing-key fail-closed, HTML/reply-to payloads, unsupported body-file, invalid recipients, and help output.\n- `1.0.8`: Soften public Resend account/default-sender wording to avoid stale pricing/free-tier/domain-setup assumptions.\n- `1.0.7`: Fix no-allowlist sample output, document bare-recipient requirement and dry-run body visibility, add 30s send timeout, and warn to verify Resend dashboard before retrying ambiguous network/timeout failures.\n- `1.0.6`: Add frontmatter version metadata, hedge rate-limit wording, document Windows 403 cleanup assertion behavior, and include sanitized dry-run/fail-closed sample outputs for eval review.\n- `1.0.5`: Public package wording and metadata cleanup; send behavior remains dry-run-first with `--send` plus recipient allowlist required for real sends.\n\nFile v1.0.9:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"resend-send-native-node\",\n  \"version\": \"1.0.9\",\n  \"publishedAt\": 1780372650748\n}\n\nFile v1.0.9:skill-card.md\n\n## Description: <br>\nSend email via Resend.com's HTTPS API - native Node.js, zero dependencies. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jwestburg](https://clawhub.ai/user/jwestburg) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent operators use this skill to draft and send outbound email through a Resend account when the recipient, subject, and body have been explicitly reviewed. It is suited to simple notifications and report-style sends, not email reading or attachment workflows. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can send external email through a configured Resend account. <br>\nMitigation: Use dry-run first, require explicit approval of the recipient, subject, and body, and only add --send after review. <br>\nRisk: Credentials and recipient permissions can expose the account to unintended sends. <br>\nMitigation: Keep RESEND_API_KEY scoped to sending and set RESEND_ALLOWED_TO narrowly for approved recipients. <br>\nRisk: Email bodies may include private logs, transcripts, or unreviewed workspace content. <br>\nMitigation: Send only curated report text and review the dry-run payload before a real send. <br>\nRisk: A timeout or ambiguous network error after submission may still result in delivery. <br>\nMitigation: Check the Resend dashboard before retrying to avoid duplicate sends. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jwestburg/resend-send-native-node) <br>\n- [Publisher profile](https://clawhub.ai/user/jwestburg) <br>\n- [Resend](https://resend.com) <br>\n- [Resend domains](https://resend.com/domains) <br>\n- [Resend pricing](https://resend.com/pricing) <br>\n- [Resend email API endpoint](https://api.resend.com/emails) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, shell commands, configuration, API calls, guidance] <br>\n**Output Format:** [Markdown guidance with inline shell commands and plain-text command output] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Real sends require --send, RESEND_API_KEY, and a RESEND_ALLOWED_TO recipient allowlist; dry-run output includes the request payload, body byte count, and SHA-256 prefix.] <br>\n\n## Skill Version(s): <br>\n1.0.9 (source: frontmatter and server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.8: 4 files, 8660 bytes\n\nFiles: scripts/send.mjs (8226b), skill-card.md (2655b), SKILL.md (9536b), _meta.json (142b)\n\nFile v1.0.8:SKILL.md\n\n---\nname: resend-send-native-node\ndescription: Send email via Resend.com's HTTPS API - native Node.js, zero dependencies. Use when the user explicitly asks to email, send a message, mail a report, or deliver a notification to an email address. Externally sends email only with --send; defaults to dry-run and requires RESEND_ALLOWED_TO allowlist for real sends. Requires RESEND_API_KEY in the process environment for real sends. No OAuth, no 2FA, no Gmail required.\nversion: 1.0.8\n---\n\n# Resend Send Native Node\n\nSend email via the Resend.com HTTPS API.\n\nNative Node.js. Zero dependencies. One POST call for real sends. Small enough to audit directly.\n\n## When to use\n\nTrigger phrases: \"email me\", \"send an email\", \"mail this to\", \"send a notification\", \"email the report\".\n\n**Use this when:**\n- The user wants to send an email fast, without Gmail OAuth or App Password pain\n- Simple \"fire and forget\" sends (no inbox reading needed)\n- The user has a Resend.com account (check Resend's current pricing/limits before relying on a specific quota)\n- Weekly/report-style outbound messages where the body is generated from explicitly reviewed text\n\n**Do NOT use this when:**\n- The user wants to READ email (this is send-only)\n- The user needs to send from a specific personal Gmail address (use a Gmail-specific skill)\n- Sensitive business emails where provenance matters (Resend's default `onboarding@resend.dev` sender looks transactional)\n- The recipient, sender, or final body has not been explicitly reviewed/approved for a real send\n\n## Safety policy for agents\n\nThis skill is send-only, but it is still externally mutating. For agent use:\n\n1. **Draft first.** Generate or inspect the exact body text before sending.\n2. **Dry-run first.** The script dry-runs by default; review the printed payload.\n3. **Explicit approval.** Use `--send` only after the user explicitly approves that exact recipient, subject, and body.\n4. **Use an allowlist.** Real sends fail closed unless `RESEND_ALLOWED_TO=addr@example.com,other@example.com` is set in the process environment for approved recipients.\n5. **No raw memory dumps.** Email only curated report text, not unfiltered memory, transcripts, logs, or private workspace context.\n\n## How to run\n\nThe script is in `scripts/send.mjs`.\n\n**Basic:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n```\n\nWithout `--send`, this prints a dry-run payload and does **not** send. Dry-run output includes the full reviewed body JSON plus body byte length and SHA-256 prefix; redact dry-run logs before sharing externally.\n\n**With from address override:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --from \"OpenClaw <onboarding@resend.dev>\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi\"\n```\n\n**HTML body:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --html --to \"you@example.com\" --subject \"Styled\" --body \"<h1>Hi</h1><p>Hello</p>\"\n```\n\n**Dry run (no send, just print the payload):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --dry-run --to \"you@example.com\" --subject \"Test\" --body \"...\"\n```\n\n**Real send (only after explicit approval):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --send --to \"you@example.com\" --subject \"Weekly report\" --body \"Approved report text\"\n```\n\n### All flags\n\n| Flag | Required? | Purpose |\n|---|---|---|\n| `--to` | yes | Comma-separated recipient addresses |\n| `--subject` | yes | Message subject |\n| `--body` | yes | Inline message body |\n| `--cc` | no | Comma-separated cc |\n| `--bcc` | no | Comma-separated bcc |\n| `--from` | no | Override sender, e.g. `\"OpenClaw <onboarding@resend.dev>\"` |\n| `--reply-to` | no | Reply-to address |\n| `--html` | no | Body is HTML instead of plain text |\n| `--dry-run` | no | Don't send; print the JSON payload |\n| `--send` | no | Actually send. Without this, the script dry-runs by default |\n| `-h`, `--help` | no | Show help |\n\nRecipients in `--to`, `--cc`, `--bcc`, and `--reply-to` must be bare email addresses. Only `--from` accepts display-name format such as `\"Reports <reports@example.com>\"`.\n\n`--body-file` is intentionally not supported in the public package. Review file contents yourself and pass approved text with `--body`.\n\n## Credentials\n\nRequires process environment values:\n\n- `RESEND_API_KEY` - starts with `re_...`\n- `RESEND_ALLOWED_TO` - comma-separated recipient allowlist for real sends\n- Real sends require `RESEND_ALLOWED_TO`; without it the script refuses `--send`\n\n**How to get one:**\n1. Sign up at https://resend.com and check the current pricing/limits for the account\n2. Go to **API Keys** in the dashboard\n3. Click **Create API Key**, name it, and choose the least-privilege sending permission available for your account\n4. Copy the key\n\nExport it in the runtime process environment:\n```powershell\n$env:RESEND_API_KEY=\"<your-resend-key>\"\n$env:RESEND_ALLOWED_TO=\"you@example.com,reports@example.com\"\n```\n\n## Sender identity\n\nBy default, emails are sent from `onboarding@resend.dev` - Resend's default sender. This may support quick testing subject to current Resend account restrictions; use a verified domain/sender for production-style mail.\n\n**For a custom domain (later, optional):**\n1. Add your domain to Resend at https://resend.com/domains\n2. Configure DNS records they provide\n3. Use a verified sender with `--from \"Reports <reports@your-verified-domain.example>\"`\n\n## What this skill does\n\n- Reads `RESEND_API_KEY` from the process environment only\n- POSTs a JSON request to `https://api.resend.com/emails`\n- Prints a one-line confirmation with the Resend message ID\n- Defaults to dry-run unless `--send` is present\n- Validates basic recipient address shape before sending\n- Enforces `RESEND_ALLOWED_TO` for real sends; fail-closed if it is missing\n- Prints body byte length and SHA-256 prefix in dry-run so reviewed content can be matched to the send\n\n## What this skill does NOT do\n\n- Does not read or manage email (this is send-only)\n- Does not read local files or support `--body-file`\n- Does not write any files\n- Does not make network calls other than to `api.resend.com`\n- Does not auto-update\n- Does not support attachments in this version\n\n## Output\n\nOn success:\n```\nsent to you@example.com (subject: Hello) - resend-id: c8f43f2a-...\n```\n\nOn failure, clear error on stderr with a non-zero exit code.\n\n## Troubleshooting\n\n- **\"RESEND_API_KEY not set\"** - create one at https://resend.com, check current pricing/limits, and export `RESEND_API_KEY` in the process environment\n- **HTTP 401** - API key is invalid or was revoked\n- **HTTP 403** - API key doesn't have send permission, or the from address can only send to the account owner until a domain is verified (check dashboard). On Windows, a Node.js cleanup assertion may appear after a 403 exit; this is cosmetic and does not indicate a successful send.\n- **HTTP 422** - the from address isn't verified on your Resend account (use `onboarding@resend.dev` or verify your own domain)\n- **HTTP 429** - rate limited; check https://resend.com/pricing or the Resend dashboard for current limits\n- **Network error or timeout** - transient, but a network/timeout/read error after the request was sent does not prove the email was not delivered. Check the Resend dashboard before retrying to avoid duplicate sends.\n\n## Sample output\n\nSanitized representative output for eval/review checks:\n\n```text\n$ node scripts/send.mjs --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n--- DRY RUN: request would be sent ---\nnote: add --send to perform a real send after explicit approval.\nbody: 8 bytes, sha256:8328c36d18b7\nWARNING: RESEND_ALLOWED_TO is not configured. Real sends will fail closed until an allowlist is set.\nPOST https://api.resend.com/emails\nAuthorization: Bearer [redacted]\n\n{\n  \"from\": \"onboarding@resend.dev\",\n  \"to\": [\n    \"you@example.com\"\n  ],\n  \"subject\": \"Hello\",\n  \"text\": \"Hi there\"\n}\n\n$ node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\nerror: RESEND_ALLOWED_TO must be set for real sends. Refusing --send without a recipient allowlist.\n\n# PowerShell:\n$env:RESEND_ALLOWED_TO=\"you@example.com\"; node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n# bash/zsh:\n# RESEND_ALLOWED_TO=\"you@example.com\" node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\nerror: RESEND_API_KEY not set in process environment. Create one at https://resend.com, check current pricing/limits, and export RESEND_API_KEY.\n```\n\n## Account limits\n\nResend pricing and free-tier limits can change. Check the current Resend dashboard/pricing page before relying on a specific daily/monthly quota or paid-tier price. New accounts commonly support quick testing from `onboarding@resend.dev`; use a verified domain/sender for production-style mail.\n\n## Changelog\n\n- `1.0.8`: Soften public Resend account/default-sender wording to avoid stale pricing/free-tier/domain-setup assumptions.\n- `1.0.7`: Fix no-allowlist sample output, document bare-recipient requirement and dry-run body visibility, add 30s send timeout, and warn to verify Resend dashboard before retrying ambiguous network/timeout failures.\n- `1.0.6`: Add frontmatter version metadata, hedge rate-limit wording, document Windows 403 cleanup assertion behavior, and include sanitized dry-run/fail-closed sample outputs for eval review.\n- `1.0.5`: Public package wording and metadata cleanup; send behavior remains dry-run-first with `--send` plus recipient allowlist required for real sends.\n\nFile v1.0.8:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"resend-send-native-node\",\n  \"version\": \"1.0.8\",\n  \"publishedAt\": 1780169211339\n}\n\nFile v1.0.8:skill-card.md\n\n## Description: <br>\nSend email via Resend.com's HTTPS API from native Node.js with dry-run default behavior, explicit --send execution, recipient allowlist enforcement, and RESEND_API_KEY required for real sends. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jwestburg](https://clawhub.ai/user/jwestburg) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, operators, and agent users use this skill to draft and send reviewed outbound email through a Resend account when they need simple send-only delivery and do not need inbox access. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can send external email through a Resend account when configured with credentials and --send. <br>\nMitigation: Use dry-run first, require explicit approval of the exact recipient, subject, and body, and keep RESEND_ALLOWED_TO limited to approved recipients. <br>\nRisk: Dry-run output prints the reviewed message body and may expose sensitive content in logs or shared transcripts. <br>\nMitigation: Redact dry-run logs before sharing externally and avoid sending raw memory, logs, transcripts, or private workspace context. <br>\nRisk: A timeout or network/read error after a request is sent may leave delivery status ambiguous and lead to duplicate sends. <br>\nMitigation: Check the Resend dashboard before retrying after ambiguous network, timeout, or response-read failures. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jwestburg/resend-send-native-node) <br>\n- [Resend](https://resend.com) <br>\n- [Resend email API endpoint](https://api.resend.com/emails) <br>\n- [Resend domains](https://resend.com/domains) <br>\n- [Resend pricing](https://resend.com/pricing) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Shell commands, Configuration, API Calls, Guidance] <br>\n**Output Format:** [Markdown guidance plus command-line output and JSON dry-run payloads] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Dry-run output includes the email body, byte length, SHA-256 prefix, redacted authorization header, and request payload; successful sends return a one-line confirmation with the Resend message ID.] <br>\n\n## Skill Version(s): <br>\n1.0.8 (source: frontmatter and server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.6: 4 files, 8041 bytes\n\nFiles: scripts/send.mjs (7534b), skill-card.md (2617b), SKILL.md (8525b), _meta.json (142b)\n\nFile v1.0.6:SKILL.md\n\n---\nname: resend-send-native-node\ndescription: Send email via Resend.com's HTTPS API - native Node.js, zero dependencies. Use when the user explicitly asks to email, send a message, mail a report, or deliver a notification to an email address. Externally sends email only with --send; defaults to dry-run and requires RESEND_ALLOWED_TO allowlist for real sends. Requires RESEND_API_KEY in the process environment for real sends. No OAuth, no 2FA, no Gmail required.\nversion: 1.0.6\n---\n\n# Resend Send Native Node\n\nSend email via the Resend.com HTTPS API.\n\nNative Node.js. Zero dependencies. One POST call for real sends. Small enough to audit directly.\n\n## When to use\n\nTrigger phrases: \"email me\", \"send an email\", \"mail this to\", \"send a notification\", \"email the report\".\n\n**Use this when:**\n- The user wants to send an email fast, without Gmail OAuth or App Password pain\n- Simple \"fire and forget\" sends (no inbox reading needed)\n- The user has a Resend.com account (check Resend's current pricing/limits before relying on a specific quota)\n- Weekly/report-style outbound messages where the body is generated from explicitly reviewed text\n\n**Do NOT use this when:**\n- The user wants to READ email (this is send-only)\n- The user needs to send from a specific personal Gmail address (use a Gmail-specific skill)\n- Sensitive business emails where provenance matters (Resend's default `onboarding@resend.dev` sender looks transactional)\n- The recipient, sender, or final body has not been explicitly reviewed/approved for a real send\n\n## Safety policy for agents\n\nThis skill is send-only, but it is still externally mutating. For agent use:\n\n1. **Draft first.** Generate or inspect the exact body text before sending.\n2. **Dry-run first.** The script dry-runs by default; review the printed payload.\n3. **Explicit approval.** Use `--send` only after the user explicitly approves that exact recipient, subject, and body.\n4. **Use an allowlist.** Real sends fail closed unless `RESEND_ALLOWED_TO=addr@example.com,other@example.com` is set in the process environment for approved recipients.\n5. **No raw memory dumps.** Email only curated report text, not unfiltered memory, transcripts, logs, or private workspace context.\n\n## How to run\n\nThe script is in `scripts/send.mjs`.\n\n**Basic:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n```\n\nWithout `--send`, this prints a dry-run payload and does **not** send.\n\n**With from address override:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --from \"OpenClaw <onboarding@resend.dev>\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi\"\n```\n\n**HTML body:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --html --to \"you@example.com\" --subject \"Styled\" --body \"<h1>Hi</h1><p>Hello</p>\"\n```\n\n**Dry run (no send, just print the payload):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --dry-run --to \"you@example.com\" --subject \"Test\" --body \"...\"\n```\n\n**Real send (only after explicit approval):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --send --to \"you@example.com\" --subject \"Weekly report\" --body \"Approved report text\"\n```\n\n### All flags\n\n| Flag | Required? | Purpose |\n|---|---|---|\n| `--to` | yes | Comma-separated recipient addresses |\n| `--subject` | yes | Message subject |\n| `--body` | yes | Inline message body |\n| `--cc` | no | Comma-separated cc |\n| `--bcc` | no | Comma-separated bcc |\n| `--from` | no | Override sender, e.g. `\"OpenClaw <onboarding@resend.dev>\"` |\n| `--reply-to` | no | Reply-to address |\n| `--html` | no | Body is HTML instead of plain text |\n| `--dry-run` | no | Don't send; print the JSON payload |\n| `--send` | no | Actually send. Without this, the script dry-runs by default |\n| `-h`, `--help` | no | Show help |\n\n`--body-file` is intentionally not supported in the public package. Review file contents yourself and pass approved text with `--body`.\n\n## Credentials\n\nRequires process environment values:\n\n- `RESEND_API_KEY` - starts with `re_...`\n- `RESEND_ALLOWED_TO` - comma-separated recipient allowlist for real sends\n- Real sends require `RESEND_ALLOWED_TO`; without it the script refuses `--send`\n\n**How to get one:**\n1. Sign up at https://resend.com and check the current pricing/limits for the account\n2. Go to **API Keys** in the dashboard\n3. Click **Create API Key**, name it, and choose the least-privilege sending permission available for your account\n4. Copy the key\n\nExport it in the runtime process environment:\n```powershell\n$env:RESEND_API_KEY=\"<your-resend-key>\"\n$env:RESEND_ALLOWED_TO=\"you@example.com,reports@example.com\"\n```\n\n## Sender identity\n\nBy default, emails are sent from `onboarding@resend.dev` - Resend's default sender. This works immediately without any domain setup.\n\n**For a custom domain (later, optional):**\n1. Add your domain to Resend at https://resend.com/domains\n2. Configure DNS records they provide\n3. Use a verified sender with `--from \"Reports <reports@your-verified-domain.example>\"`\n\n## What this skill does\n\n- Reads `RESEND_API_KEY` from the process environment only\n- POSTs a JSON request to `https://api.resend.com/emails`\n- Prints a one-line confirmation with the Resend message ID\n- Defaults to dry-run unless `--send` is present\n- Validates basic recipient address shape before sending\n- Enforces `RESEND_ALLOWED_TO` for real sends; fail-closed if it is missing\n- Prints body byte length and SHA-256 prefix in dry-run so reviewed content can be matched to the send\n\n## What this skill does NOT do\n\n- Does not read or manage email (this is send-only)\n- Does not read local files or support `--body-file`\n- Does not write any files\n- Does not make network calls other than to `api.resend.com`\n- Does not auto-update\n- Does not support attachments in this version\n\n## Output\n\nOn success:\n```\nsent to you@example.com (subject: Hello) - resend-id: c8f43f2a-...\n```\n\nOn failure, clear error on stderr with a non-zero exit code.\n\n## Troubleshooting\n\n- **\"RESEND_API_KEY not set\"** - get one at https://resend.com and export `RESEND_API_KEY` in the process environment\n- **HTTP 401** - API key is invalid or was revoked\n- **HTTP 403** - API key doesn't have send permission, or the from address can only send to the account owner until a domain is verified (check dashboard). On Windows, a Node.js cleanup assertion may appear after a 403 exit; this is cosmetic and does not indicate a successful send.\n- **HTTP 422** - the from address isn't verified on your Resend account (use `onboarding@resend.dev` or verify your own domain)\n- **HTTP 429** - rate limited; check https://resend.com/pricing or the Resend dashboard for current limits\n- **Network error** - transient; retry\n\n## Sample output\n\nSanitized representative output for eval/review checks:\n\n```text\n$ node scripts/send.mjs --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n--- DRY RUN: request would be sent ---\nnote: add --send to perform a real send after explicit approval.\nbody: 8 bytes, sha256:8328c36d18b7\nWARNING: RESEND_ALLOWED_TO is not configured. Real sends will fail closed until an allowlist is set.\nPOST https://api.resend.com/emails\nAuthorization: Bearer [redacted]\n\n{\n  \"from\": \"onboarding@resend.dev\",\n  \"to\": [\n    \"you@example.com\"\n  ],\n  \"subject\": \"Hello\",\n  \"text\": \"Hi there\"\n}\n\n$ node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\nerror: recipient not in RESEND_ALLOWED_TO allowlist: you@example.com\n\n# PowerShell:\n$env:RESEND_ALLOWED_TO=\"you@example.com\"; node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n# bash/zsh:\n# RESEND_ALLOWED_TO=\"you@example.com\" node scripts/send.mjs --send --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\nerror: RESEND_API_KEY not set in process environment. Get one free at https://resend.com and export RESEND_API_KEY.\n```\n\n## Account limits\n\nResend pricing and free-tier limits can change. Check the current Resend dashboard/pricing page before relying on a specific daily/monthly quota or paid-tier price. New accounts commonly support quick testing from `onboarding@resend.dev`; use a verified domain/sender for production-style mail.\n\n## Changelog\n\n- `1.0.6`: Add frontmatter version metadata, hedge rate-limit wording, document Windows 403 cleanup assertion behavior, and include sanitized dry-run/fail-closed sample outputs for eval review.\n- `1.0.5`: Public package wording and metadata cleanup; send behavior remains dry-run-first with `--send` plus recipient allowlist required for real sends.\n\nFile v1.0.6:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"resend-send-native-node\",\n  \"version\": \"1.0.6\",\n  \"publishedAt\": 1779763706752\n}\n\nFile v1.0.6:skill-card.md\n\n## Description: <br>\nSends email through Resend.com's HTTPS API using native Node.js, with dry-run defaults, recipient allowlisting for real sends, and RESEND_API_KEY credentials. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jwestburg](https://clawhub.ai/user/jwestburg) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agents use this skill to send explicitly reviewed outbound email, notifications, or report text through a Resend account without Gmail OAuth setup. It is send-only and is not intended for reading mail, attachments, or unreviewed sensitive content. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can send external email when invoked with --send. <br>\nMitigation: Review the exact recipient, subject, and body in dry-run output before sending, and require explicit user approval for that payload. <br>\nRisk: Resend API credentials can authorize outbound email. <br>\nMitigation: Use a least-privilege API key stored only in the process environment and rotate or revoke it if exposure is suspected. <br>\nRisk: Unintended recipients or broad distribution could disclose information. <br>\nMitigation: Keep RESEND_ALLOWED_TO narrow; real sends fail closed unless every to, cc, and bcc recipient is allowlisted. <br>\nRisk: Emailing raw logs, transcripts, secrets, or workspace context can leak sensitive data. <br>\nMitigation: Send only curated, explicitly reviewed message text and avoid raw memory dumps or unfiltered operational logs. <br>\n\n\n## Reference(s): <br>\n- [ClawHub release page](https://clawhub.ai/jwestburg/resend-send-native-node) <br>\n- [Resend](https://resend.com) <br>\n- [Resend domains](https://resend.com/domains) <br>\n- [Resend pricing](https://resend.com/pricing) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown instructions and terminal text output] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Real sends require explicit --send, RESEND_API_KEY, and RESEND_ALLOWED_TO; dry-run output includes the request payload, body byte length, and a SHA-256 prefix.] <br>\n\n## Skill Version(s): <br>\n1.0.6 (source: frontmatter and server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.5: 3 files, 6004 bytes\n\nFiles: scripts/send.mjs (7534b), SKILL.md (6534b), _meta.json (142b)\n\nFile v1.0.5:SKILL.md\n\n---\nname: resend-send-native-node\ndescription: Send email via Resend.com's HTTPS API - native Node.js, zero dependencies. Use when the user explicitly asks to email, send a message, mail a report, or deliver a notification to an email address. Externally sends email only with --send; defaults to dry-run and requires RESEND_ALLOWED_TO allowlist for real sends. Requires RESEND_API_KEY in the process environment for real sends. No OAuth, no 2FA, no Gmail required.\n---\n\n# Resend Send Native Node\n\nSend email via the Resend.com HTTPS API.\n\nNative Node.js. Zero dependencies. One POST call for real sends. Small enough to audit directly.\n\n## When to use\n\nTrigger phrases: \"email me\", \"send an email\", \"mail this to\", \"send a notification\", \"email the report\".\n\n**Use this when:**\n- The user wants to send an email fast, without Gmail OAuth or App Password pain\n- Simple \"fire and forget\" sends (no inbox reading needed)\n- The user has a Resend.com account (free tier: 3,000 emails/month)\n- Weekly/report-style outbound messages where the body is generated from explicitly reviewed text\n\n**Do NOT use this when:**\n- The user wants to READ email (this is send-only)\n- The user needs to send from a specific personal Gmail address (use a Gmail-specific skill)\n- Sensitive business emails where provenance matters (Resend's default `onboarding@resend.dev` sender looks transactional)\n- The recipient, sender, or final body has not been explicitly reviewed/approved for a real send\n\n## Safety policy for agents\n\nThis skill is send-only, but it is still externally mutating. For agent use:\n\n1. **Draft first.** Generate or inspect the exact body text before sending.\n2. **Dry-run first.** The script dry-runs by default; review the printed payload.\n3. **Explicit approval.** Use `--send` only after the user explicitly approves that exact recipient, subject, and body.\n4. **Use an allowlist.** Real sends fail closed unless `RESEND_ALLOWED_TO=addr@example.com,other@example.com` is set in the process environment for approved recipients.\n5. **No raw memory dumps.** Email only curated report text, not unfiltered memory, transcripts, logs, or private workspace context.\n\n## How to run\n\nThe script is in `scripts/send.mjs`.\n\n**Basic:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n```\n\nWithout `--send`, this prints a dry-run payload and does **not** send.\n\n**With from address override:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --from \"OpenClaw <onboarding@resend.dev>\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi\"\n```\n\n**HTML body:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --html --to \"you@example.com\" --subject \"Styled\" --body \"<h1>Hi</h1><p>Hello</p>\"\n```\n\n**Dry run (no send, just print the payload):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --dry-run --to \"you@example.com\" --subject \"Test\" --body \"...\"\n```\n\n**Real send (only after explicit approval):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --send --to \"you@example.com\" --subject \"Weekly report\" --body \"Approved report text\"\n```\n\n### All flags\n\n| Flag | Required? | Purpose |\n|---|---|---|\n| `--to` | yes | Comma-separated recipient addresses |\n| `--subject` | yes | Message subject |\n| `--body` | yes | Inline message body |\n| `--cc` | no | Comma-separated cc |\n| `--bcc` | no | Comma-separated bcc |\n| `--from` | no | Override sender, e.g. `\"OpenClaw <onboarding@resend.dev>\"` |\n| `--reply-to` | no | Reply-to address |\n| `--html` | no | Body is HTML instead of plain text |\n| `--dry-run` | no | Don't send; print the JSON payload |\n| `--send` | no | Actually send. Without this, the script dry-runs by default |\n| `-h`, `--help` | no | Show help |\n\n`--body-file` is intentionally not supported in the public package. Review file contents yourself and pass approved text with `--body`.\n\n## Credentials\n\nRequires process environment values:\n\n- `RESEND_API_KEY` - starts with `re_...`\n- `RESEND_ALLOWED_TO` - comma-separated recipient allowlist for real sends\n- Real sends require `RESEND_ALLOWED_TO`; without it the script refuses `--send`\n\n**How to get one:**\n1. Sign up at https://resend.com (free - 3,000 emails/month)\n2. Go to **API Keys** in the dashboard\n3. Click **Create API Key**, name it, and choose the least-privilege sending permission available for your account\n4. Copy the key\n\nExport it in the runtime process environment:\n```powershell\n$env:RESEND_API_KEY=\"<your-resend-key>\"\n$env:RESEND_ALLOWED_TO=\"you@example.com,reports@example.com\"\n```\n\n## Sender identity\n\nBy default, emails are sent from `onboarding@resend.dev` - Resend's default sender. This works immediately without any domain setup.\n\n**For a custom domain (later, optional):**\n1. Add your domain to Resend at https://resend.com/domains\n2. Configure DNS records they provide\n3. Use a verified sender with `--from \"Reports <reports@your-verified-domain.example>\"`\n\n## What this skill does\n\n- Reads `RESEND_API_KEY` from the process environment only\n- POSTs a JSON request to `https://api.resend.com/emails`\n- Prints a one-line confirmation with the Resend message ID\n- Defaults to dry-run unless `--send` is present\n- Validates basic recipient address shape before sending\n- Enforces `RESEND_ALLOWED_TO` for real sends; fail-closed if it is missing\n- Prints body byte length and SHA-256 prefix in dry-run so reviewed content can be matched to the send\n\n## What this skill does NOT do\n\n- Does not read or manage email (this is send-only)\n- Does not read local files or support `--body-file`\n- Does not write any files\n- Does not make network calls other than to `api.resend.com`\n- Does not auto-update\n- Does not support attachments in this version\n\n## Output\n\nOn success:\n```\nsent to you@example.com (subject: Hello) - resend-id: c8f43f2a-...\n```\n\nOn failure, clear error on stderr with a non-zero exit code.\n\n## Troubleshooting\n\n- **\"RESEND_API_KEY not set\"** - get one at https://resend.com and export `RESEND_API_KEY` in the process environment\n- **HTTP 401** - API key is invalid or was revoked\n- **HTTP 403** - API key doesn't have send permission (check dashboard)\n- **HTTP 422** - the from address isn't verified on your Resend account (use `onboarding@resend.dev` or verify your own domain)\n- **HTTP 429** - rate limited (free tier: 100/day, 3,000/month)\n- **Network error** - transient; retry\n\n## Free tier limits\n\n- 3,000 emails/month\n- 100 emails/day\n- Sends from `onboarding@resend.dev` (no domain needed)\n- For higher limits + custom domains, paid tiers start at $20/month\n\nFile v1.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"resend-send-native-node\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1778254941161\n}\n\nArchive v1.0.4: 3 files, 5996 bytes\n\nFiles: scripts/send.mjs (7534b), SKILL.md (6493b), _meta.json (142b)\n\nFile v1.0.4:SKILL.md\n\n---\nname: resend-send-native-node\ndescription: Send email via Resend.com's HTTPS API - native Node.js, zero dependencies. Use when the user explicitly asks to email, send a message, mail a report, or deliver a notification to an email address. Externally sends email only with --send; defaults to dry-run and requires RESEND_ALLOWED_TO allowlist for real sends. Requires RESEND_API_KEY in the process environment for real sends. No OAuth, no 2FA, no Gmail required.\n---\n\n# Resend Send Native Node\n\nSend email via the Resend.com HTTPS API.\n\nNative Node.js. Zero dependencies. One POST call for real sends. Small enough to audit directly.\n\n## When to use\n\nTrigger phrases: \"email me\", \"send an email\", \"mail this to\", \"send a notification\", \"email the report\".\n\n**Use this when:**\n- The user wants to send an email fast, without Gmail OAuth or App Password pain\n- Simple \"fire and forget\" sends (no inbox reading needed)\n- The user has a Resend.com account (free tier: 3,000 emails/month)\n- Weekly/report-style outbound messages where the body is generated from explicitly reviewed text\n\n**Do NOT use this when:**\n- The user wants to READ email (this is send-only)\n- The user needs to send from a specific personal Gmail address (use a Gmail-specific skill)\n- Sensitive business emails where provenance matters (Resend's default `onboarding@resend.dev` sender looks transactional)\n- The recipient, sender, or final body has not been explicitly reviewed/approved for a real send\n\n## Safety policy for agents\n\nThis skill is send-only, but it is still externally mutating. For agent use:\n\n1. **Draft first.** Generate or inspect the exact body text before sending.\n2. **Dry-run first.** The script dry-runs by default; review the printed payload.\n3. **Explicit approval.** Use `--send` only after the user explicitly approves that exact recipient, subject, and body.\n4. **Use an allowlist.** Real sends fail closed unless `RESEND_ALLOWED_TO=addr@example.com,other@example.com` is set in the process environment for approved recipients.\n5. **No raw memory dumps.** Email only curated report text, not unfiltered memory, transcripts, logs, or private workspace context.\n\n## How to run\n\nThe script is in `scripts/send.mjs`.\n\n**Basic:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n```\n\nWithout `--send`, this prints a dry-run payload and does **not** send.\n\n**With from address override:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --from \"OpenClaw <onboarding@resend.dev>\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi\"\n```\n\n**HTML body:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --html --to \"you@example.com\" --subject \"Styled\" --body \"<h1>Hi</h1><p>Hello</p>\"\n```\n\n**Dry run (no send, just print the payload):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --dry-run --to \"you@example.com\" --subject \"Test\" --body \"...\"\n```\n\n**Real send (only after explicit approval):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --send --to \"you@example.com\" --subject \"Weekly report\" --body \"Approved report text\"\n```\n\n### All flags\n\n| Flag | Required? | Purpose |\n|---|---|---|\n| `--to` | yes | Comma-separated recipient addresses |\n| `--subject` | yes | Message subject |\n| `--body` | yes | Inline message body |\n| `--cc` | no | Comma-separated cc |\n| `--bcc` | no | Comma-separated bcc |\n| `--from` | no | Override sender, e.g. `\"OpenClaw <onboarding@resend.dev>\"` |\n| `--reply-to` | no | Reply-to address |\n| `--html` | no | Body is HTML instead of plain text |\n| `--dry-run` | no | Don't send; print the JSON payload |\n| `--send` | no | Actually send. Without this, the script dry-runs by default |\n| `-h`, `--help` | no | Show help |\n\n`--body-file` is intentionally not supported in the public package. Review file contents yourself and pass approved text with `--body`.\n\n## Credentials\n\nRequires process environment values:\n\n- `RESEND_API_KEY` - starts with `re_...`\n- `RESEND_ALLOWED_TO` - comma-separated recipient allowlist for real sends\n- Real sends require `RESEND_ALLOWED_TO`; without it the script refuses `--send`\n\n**How to get one:**\n1. Sign up at https://resend.com (free - 3,000 emails/month)\n2. Go to **API Keys** in the dashboard\n3. Click **Create API Key**, name it, and choose the least-privilege sending permission available for your account\n4. Copy the key\n\nExport it in the runtime process environment:\n```powershell\n$env:RESEND_API_KEY=\"<your-resend-key>\"\n$env:RESEND_ALLOWED_TO=\"you@example.com,reports@example.com\"\n```\n\n## Sender identity\n\nBy default, emails are sent from `onboarding@resend.dev` - Resend's default sender. This works immediately without any domain setup.\n\n**For a custom domain (later, optional):**\n1. Add your domain to Resend at https://resend.com/domains\n2. Configure DNS records they provide\n3. Use `--from \"Henry <henry@yourdomain.com>\"`\n\n## What this skill does\n\n- Reads `RESEND_API_KEY` from the process environment only\n- POSTs a JSON request to `https://api.resend.com/emails`\n- Prints a one-line confirmation with the Resend message ID\n- Defaults to dry-run unless `--send` is present\n- Validates basic recipient address shape before sending\n- Enforces `RESEND_ALLOWED_TO` for real sends; fail-closed if it is missing\n- Prints body byte length and SHA-256 prefix in dry-run so reviewed content can be matched to the send\n\n## What this skill does NOT do\n\n- Does not read or manage email (this is send-only)\n- Does not read local files or support `--body-file`\n- Does not write any files\n- Does not make network calls other than to `api.resend.com`\n- Does not auto-update\n- Does not support attachments in this version\n\n## Output\n\nOn success:\n```\nsent to you@example.com (subject: Hello) - resend-id: c8f43f2a-...\n```\n\nOn failure, clear error on stderr with a non-zero exit code.\n\n## Troubleshooting\n\n- **\"RESEND_API_KEY not set\"** - get one at https://resend.com and export `RESEND_API_KEY` in the process environment\n- **HTTP 401** - API key is invalid or was revoked\n- **HTTP 403** - API key doesn't have send permission (check dashboard)\n- **HTTP 422** - the from address isn't verified on your Resend account (use `onboarding@resend.dev` or verify your own domain)\n- **HTTP 429** - rate limited (free tier: 100/day, 3,000/month)\n- **Network error** - transient; retry\n\n## Free tier limits\n\n- 3,000 emails/month\n- 100 emails/day\n- Sends from `onboarding@resend.dev` (no domain needed)\n- For higher limits + custom domains, paid tiers start at $20/month\n\nFile v1.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"resend-send-native-node\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1778192229180\n}\n\nArchive v1.0.3: 3 files, 5997 bytes\n\nFiles: scripts/send.mjs (7534b), SKILL.md (6493b), _meta.json (142b)\n\nFile v1.0.3:SKILL.md\n\n---\nname: resend-send-native-node\ndescription: Send email via Resend.com's HTTPS API - native Node.js, zero dependencies. Use when the user explicitly asks to email, send a message, mail a report, or deliver a notification to an email address. Externally sends email only with --send; defaults to dry-run and requires RESEND_ALLOWED_TO allowlist for real sends. Requires RESEND_API_KEY in the process environment for real sends. No OAuth, no 2FA, no Gmail required.\n---\n\n# Resend Send Native Node\n\nSend email via the Resend.com HTTPS API.\n\nNative Node.js. Zero dependencies. One POST call for real sends. Small enough to audit directly.\n\n## When to use\n\nTrigger phrases: \"email me\", \"send an email\", \"mail this to\", \"send a notification\", \"email the report\".\n\n**Use this when:**\n- The user wants to send an email fast, without Gmail OAuth or App Password pain\n- Simple \"fire and forget\" sends (no inbox reading needed)\n- The user has a Resend.com account (free tier: 3,000 emails/month)\n- Weekly/report-style outbound messages where the body is generated from explicitly reviewed text\n\n**Do NOT use this when:**\n- The user wants to READ email (this is send-only)\n- The user needs to send from a specific personal Gmail address (use a Gmail-specific skill)\n- Sensitive business emails where provenance matters (Resend's default `onboarding@resend.dev` sender looks transactional)\n- The recipient, sender, or final body has not been explicitly reviewed/approved for a real send\n\n## Safety policy for agents\n\nThis skill is send-only, but it is still externally mutating. For agent use:\n\n1. **Draft first.** Generate or inspect the exact body text before sending.\n2. **Dry-run first.** The script dry-runs by default; review the printed payload.\n3. **Explicit approval.** Use `--send` only after the user explicitly approves that exact recipient, subject, and body.\n4. **Use an allowlist.** Real sends fail closed unless `RESEND_ALLOWED_TO=addr@example.com,other@example.com` is set in the process environment for approved recipients.\n5. **No raw memory dumps.** Email only curated report text, not unfiltered memory, transcripts, logs, or private workspace context.\n\n## How to run\n\nThe script is in `scripts/send.mjs`.\n\n**Basic:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\"\n```\n\nWithout `--send`, this prints a dry-run payload and does **not** send.\n\n**With from address override:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --from \"OpenClaw <onboarding@resend.dev>\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi\"\n```\n\n**HTML body:**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --html --to \"you@example.com\" --subject \"Styled\" --body \"<h1>Hi</h1><p>Hello</p>\"\n```\n\n**Dry run (no send, just print the payload):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --dry-run --to \"you@example.com\" --subject \"Test\" --body \"...\"\n```\n\n**Real send (only after explicit approval):**\n```powershell\nnode \"<skill-dir>/scripts/send.mjs\" --send --to \"you@example.com\" --subject \"Weekly report\" --body \"Approved report text\"\n```\n\n### All flags\n\n| Flag | Required? | Purpose |\n|---|---|---|\n| `--to` | yes | Comma-separated recipient addresses |\n| `--subject` | yes | Message subject |\n| `--body` | yes | Inline message body |\n| `--cc` | no | Comma-separated cc |\n| `--bcc` | no | Comma-separated bcc |\n| `--from` | no | Override sender, e.g. `\"OpenClaw <onboarding@resend.dev>\"` |\n| `--reply-to` | no | Reply-to address |\n| `--html` | no | Body is HTML instead of plain text |\n| `--dry-run` | no | Don't send; print the JSON payload |\n| `--send` | no | Actually send. Without this, the script dry-runs by default |\n| `-h`, `--help` | no | Show help |\n\n`--body-file` is intentionally not supported in the public package. Review file contents yourself and pass approved text with `--body`.\n\n## Credentials\n\nRequires process environment values:\n\n- `RESEND_API_KEY` - starts with `re_...`\n- `RESEND_ALLOWED_TO` - comma-separated recipient allowlist for real sends\n- Real sends require `RESEND_ALLOWED_TO`; without it the script refuses `--send`\n\n**How to get one:**\n1. Sign up at https://resend.com (free - 3,000 emails/month)\n2. Go to **API Keys** in the dashboard\n3. Click **Create API Key**, name it, and choose the least-privilege sending permission available for your account\n4. Copy the key\n\nExport it in the runtime process environment:\n```powershell\n$env:RESEND_API_KEY=\"<your-resend-key>\"\n$env:RESEND_ALLOWED_TO=\"you@example.com,reports@example.com\"\n```\n\n## Sender identity\n\nBy default, emails are sent from `onboarding@resend.dev` - Resend's default sender. This works immediately without any domain setup.\n\n**For a custom domain (later, optional):**\n1. Add your domain to Resend at https://resend.com/domains\n2. Configure DNS records they provide\n3. Use `--from \"Henry <henry@yourdomain.com>\"`\n\n## What this skill does\n\n- Reads `RESEND_API_KEY` from the process environment only\n- POSTs a JSON request to `https://api.resend.com/emails`\n- Prints a one-line confirmation with the Resend message ID\n- Defaults to dry-run unless `--send` is present\n- Validates basic recipient address shape before sending\n- Enforces `RESEND_ALLOWED_TO` for real sends; fail-closed if it is missing\n- Prints body byte length and SHA-256 prefix in dry-run so reviewed content can be matched to the send\n\n## What this skill does NOT do\n\n- Does not read or manage email (this is send-only)\n- Does not read local files or support `--body-file`\n- Does not write any files\n- Does not make network calls other than to `api.resend.com`\n- Does not auto-update\n- Does not support attachments in this version\n\n## Output\n\nOn success:\n```\nsent to you@example.com (subject: Hello) - resend-id: c8f43f2a-...\n```\n\nOn failure, clear error on stderr with a non-zero exit code.\n\n## Troubleshooting\n\n- **\"RESEND_API_KEY not set\"** - get one at https://resend.com and export `RESEND_API_KEY` in the process environment\n- **HTTP 401** - API key is invalid or was revoked\n- **HTTP 403** - API key doesn't have send permission (check dashboard)\n- **HTTP 422** - the from address isn't verified on your Resend account (use `onboarding@resend.dev` or verify your own domain)\n- **HTTP 429** - rate limited (free tier: 100/day, 3,000/month)\n- **Network error** - transient; retry\n\n## Free tier limits\n\n- 3,000 emails/month\n- 100 emails/day\n- Sends from `onboarding@resend.dev` (no domain needed)\n- For higher limits + custom domains, paid tiers start at $20/month\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"resend-send-native-node\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1778082662599\n}","readmeExcerpt":"Skill: resend-send-native-node Owner: jwestburg Summary: Send email via Resend.com's HTTPS API - native Node.js, zero dependencies. Use when the user explicitly asks to email, send a message, mail a report, or deliver a notification to an email address. Externally sends email only with --send; defaults to dry-run and requires RESEND_ALLOWED_TO allowlist for real sends. Requires RESEND_API_KEY in the process environme","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"argv: [\"<skill-dir>/scripts/send.mjs\", \"--json\", \"--dry-run\", \"--input-json-stdin\"]\nstdin JSON: {\"to\":[\"you@example.com\"],\"subject\":\"Reviewed subject\",\"body\":\"Approved body text\"}"},{"language":"powershell","snippet":"node \"<skill-dir>/scripts/send.mjs\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi there\""},{"language":"powershell","snippet":"node \"<skill-dir>/scripts/send.mjs\" --from \"Example Sender <onboarding@resend.dev>\" --to \"you@example.com\" --subject \"Hello\" --body \"Hi\""},{"language":"powershell","snippet":"node \"<skill-dir>/scripts/send.mjs\" --html --to \"you@example.com\" --subject \"Styled\" --body \"<h1>Hi</h1><p>Hello</p>\""},{"language":"powershell","snippet":"node \"<skill-dir>/scripts/send.mjs\" --dry-run --to \"you@example.com\" --subject \"Test\" --body \"...\""},{"language":"powershell","snippet":"node \"<skill-dir>/scripts/send.mjs\" --send --to \"you@example.com\" --subject \"Weekly report\" --body \"Approved report text\""}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: resend-send-native-node\ndescription: Send email via Resend.com's HTTPS API - native Node.js, zero dependencies. Use when the user explicitly asks to email, send a message, mail a report, or deliver a notification to an email address. Externally sends email only with --send; defaults to dry-run and requires RESEND_ALLOWED_TO allowlist for real sends. Requires RESEND_API_KEY in the process environment for real sends. No OAuth, no 2FA, no Gmail required.\nversion: 1.0.20\nrisk_class: external-email-send-dry-run-default-send-gated\n---\n\n# Resend Send Native Node\n\nSend email via the Resend.com HTTPS API.\n\nNative Node.js. Zero dependencies. One POST call for real sends. Small enough to audit directly.\n\n## When to use\n\nTrigger phrases: \"email me\", \"send an email\", \"mail this to\", \"send a notification\", \"email the report\".\n\n**Use this when:**\n- The user wants to send an email fast, without Gmail OAuth or App Password pain\n- Simple \"fire and forget\" sends (no inbox reading needed)\n- The user has a Resend.com account (check Resend's current pricing/limits before relying on a specific quota)\n- Weekly/report-style outbound messages where the body is generated from explicitly reviewed text\n\n**Do NOT use this when:**\n- The user wants to READ email (this is send-only)\n- The user needs to send from a specific personal Gmail address (use a Gmail-specific skill)\n- Sensitive business emails where provenance matters (Resend's default `onboarding@resend.dev` sender looks transactional)\n- The recipient, sender, or final body has not been explicitly reviewed/approved for a real send\n\n## Safety policy for agents\n\nThis skill is send-only, but it is still externally mutating. For agent use:\n\n1. **Draft first.** Generate or inspect the exact body text before sending.\n2. **Dry-run first.** The script dry-runs by default; review the printed payload.\n3. **Explicit approval.** Use `--send` only after the user explicitly approves the exact `to`, `cc`, `bcc`, `from`, `reply-to`, `subject`, and body. Treat `reply-to` as response-routing control and review display-name text in `from` for spoof-like wording before any real send.\n4. **Use an allowlist.** Real sends fail closed unless `RESEND_ALLOWED_TO=addr@example.com,other@example.com` is set in the process environment for approved recipients. Treat `RESEND_ALLOWED_TO` as an operator-controlled, approval-scoped guard; agents must not broaden or set it merely to make a send succeed unless the user explicitly approves that exact allowlist change.\n5. **No raw memory dumps.** Email only curated report text, not unfiltered memory, transcripts, logs, or private workspace context.\n\n## How to run\n\nThe script is in `scripts/send.mjs`. Requires Node.js 18+ because real sends use native `fetch` and `AbortController`.\n\nFor operator workflows, prefer `--json` so dry-runs and real sends produce a stable machine-readable receipt with `mode`, `sent`, recipients, subject, body byte count, full body SHA-256, SHA-256 prefix, allowlist status,"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"resend-send-native-node\",\n  \"version\": \"1.0.20\",\n  \"publishedAt\": 1789093606437\n}"},{"path":"skill-card.md","content":"## Description:\n\nResend Send Native Node sends email via Resend.com's HTTPS API using native Node.js, with dry-run defaults and gated real sends.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jwestburg](https://clawhub.ai/user/jwestburg)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill when a user explicitly asks to send an email, message, report, or notification through Resend. It supports previewing the exact payload before delivery and requires explicit send approval plus a recipient allowlist for real sends.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Real email sends are externally mutating and may deliver incorrect or unapproved content.\n\nMitigation: Draft and dry-run first, review the exact recipients, headers, subject, and body, and use --send only after explicit user approval.\n\nRisk: Emailing raw logs, transcripts, secrets, or private workspace context can expose sensitive information through Resend.\n\nMitigation: Send only curated, reviewed content that the user is comfortable transmitting externally.\n\nRisk: A broad or agent-modified recipient allowlist can bypass the intended recipient control for real sends.\n\nMitigation: Keep RESEND_ALLOWED_TO narrow and operator-controlled, and do not widen it merely to make a send succeed.\n\nRisk: Network timeouts or server-side errors can leave delivery status ambiguous and cause duplicate emails if retried blindly.\n\nMitigation: Check the Resend dashboard before retrying any request that may have reached Resend.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/jwestburg/skills/resend-send-native-node)\n- [Resend](https://resend.com)\n- [Resend domains](https://resend.com/domains)\n- [Resend pricing](https://resend.com/pricing)\n- [Resend emails API endpoint](https://api.resend.com/emails)\n\n## Skill Output:\n\n**Output Type(s):** [Text, JSON, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Plain text or JSON receipts, with Markdown usage guidance and command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Dry-run receipts include payload details, body byte count, body SHA-256 values, and allowlist status; successful sends include the Resend message ID.]\n\n## Skill Version(s):\n\n1.0.20 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1431,"uniquenessScore":43,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T05:27:05.264Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T05:27:05.264Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:43:00.422Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}