-
Parse the request from ${var}: to (required — one valid email address), optional cc, optional subject, and the about (the goal / what to say). If to or the purpose is missing, check memory/outreach.md for a queued request; if still nothing, log SEND_EMAIL_SKIP: no recipient/purpose and stop.
-
Sanity-check the recipient. A single, plausible, individual address with a real reason to be contacted. Refuse scraped addresses, list blasts, or anything spam-shaped → SEND_EMAIL_REFUSED.
-
Compose the email — plain text, in the operator's voice (soul/SOUL.md + soul/STYLE.md; neutral tone if soul is empty). Short, specific, one clear ask or message; add a subject if none was given. The body is exactly what gets sent — keep any reasoning or operator-only notes OUT of it (those live only in the log).
-
Save a review copy of the composed email (human-readable: to / cc / subject / body) to memory/drafts/send-email-latest.md (overwrite; mkdir -p memory/drafts). This is the stable path a later revise: reply reloads — it is not the send path, so a revision refines this copy and never re-sends. Set SLUG = recipient-local-part + a short subject hash (the ledger dedup + idempotency key).
-
Kill-switch. If $DISCLOSURE_EMAIL_PAUSED is one of 1/true/yes/on → SEND_EMAIL_SKIP: paused, stop.
-
Config. Presence-check with the ${VAR:+x} form — a bare $RESEND_API_KEY trips the secret-expansion analyzer and falsely reads as unset (same idiom narrative-tracker documents). If either is unset → SEND_EMAIL_SKIP: resend not configured, stop (nothing sent, nothing lost):
{ [ -n "${RESEND_API_KEY:+x}" ] && [ -n "${RESEND_FROM:+x}" ]; } || { echo "SEND_EMAIL_SKIP: resend not configured"; exit 0; }
-
Ledger + daily cap. Seed memory/email-log.json to [] if missing/corrupt, then stop if the count is unreadable (fail closed) or today's budget is spent (cap default 1):
TODAY=$(date -u +%F)
SENT_TODAY=$(jq --arg d "$TODAY" '[.[]|select((.sent_at//"")|startswith($d))]|length' memory/email-log.json 2>/dev/null)
case "$SENT_TODAY" in ''|*[!0-9]*) echo "SEND_EMAIL_SKIP: ledger unreadable"; exit 0;; esac
[ "$SENT_TODAY" -lt "${DISCLOSURE_EMAIL_DAILY_CAP:-1}" ] || { echo "SEND_EMAIL_SKIP: daily cap"; exit 0; }
-
Dedup. Stop unless the ledger check cleanly reports "not present" — a jq error is fail closed (stop), never assume no-dup:
jq -e --arg s "$SLUG" 'any(.[];.slug==$s)' memory/email-log.json >/dev/null 2>&1
case $? in 0) echo "SEND_EMAIL_SKIP: dup"; exit 0;; 1) : ;; *) echo "SEND_EMAIL_SKIP: ledger unreadable"; exit 0;; esac
-
Recipient sanity. $TO must match ^[^@[:space:]]+@[^@[:space:]]+\.[^@[:space:]]+$ (grep -qE) → else SEND_EMAIL_REFUSED: bad recipient, stop.
-
Cooldown. If $TO was emailed within ${DISCLOSURE_EMAIL_COOLDOWN_DAYS:-7} days (find its latest .sent_at in the ledger and compare with a python3 datetime diff) → SEND_EMAIL_SKIP: cooldown, stop.
-
Secret tripwire. If subject+body match grep -qE '(sk-[A-Za-z0-9]{20}|re_[A-Za-z0-9]{8}[A-Za-z0-9_]{12}|gh[pousr]_[A-Za-z0-9]{20}|AKIA[0-9A-Z]{16}|AIza[0-9A-Za-z_-]{20}|-----BEGIN [A-Z ]*PRIVATE KEY-----)' → SEND_EMAIL_BLOCKED: secret in body, stop (never exfiltrate a token).
-
Build cc = the request's cc (comma-list or array) plus $RESEND_CC (operator audit copy), with blanks and $TO removed and deduped (jq).
-
Build payload + send. Build the JSON with python3 reading RESEND_FROM/RESEND_REPLY_TO from os.environ — so no secret-named var ever lands on a command line (a --arg from "$RESEND_FROM" would risk the analyzer block). Then POST with ./secretcurl (the {RESEND_API_KEY} header placeholder is substituted inside the script; $PAYLOAD carries only the already-resolved from-address, not a secret-named expansion). slug is the idempotency key so a re-run can't double-send:
PAYLOAD=$(python3 - "$TO" "$SUBJECT" "$BODY" "$CC_JSON" <<'PY'
import os, sys, json
to, subject, text, cc = sys.argv[1], sys.argv[2], sys.argv[3], json.loads(sys.argv[4] or "[]")
p = {"from": os.environ["RESEND_FROM"], "to": [to], "subject": subject, "text": text}
if os.environ.get("RESEND_REPLY_TO"): p["reply_to"] = os.environ["RESEND_REPLY_TO"]
if cc: p["cc"] = cc
print(json.dumps(p))
PY
)
./secretcurl -sS --max-time 30 -w 'http=%{http_code}\n' -X POST "https://api.resend.com/emails" \
-H "Authorization: Bearer {RESEND_API_KEY}" -H "Content-Type: application/json" \
-H "Idempotency-Key: $SLUG" -d "$PAYLOAD"
Print http=<code>. A response body with .id = sent; no .id (or non-2xx) = failed → SEND_EMAIL_FAILED: <message>, stop (it's a one-off — nothing to retry).
-
Record. On success only, append one row to memory/email-log.json (via python3 read-modify-write or the Write tool — there is no mv): {slug:$SLUG, to:$TO, subject:$SUBJECT, resend_id:<id>, sent_at:<date -u +%FT%TZ>}.
-
Notify the operator (audit copy) via ./notify:
email sent → <to>: <subject>
Then offer a revision — a separate ./notify (dedup: once per produced draft — scan the last ~2 days of memory/logs/ for a FORCE_REPLY_OFFERED: revise line dated ${today} and skip if present):
./notify "Want to refine this email? Reply with a change and I'll revise the draft (won't re-send)." \
--force-reply --placeholder "e.g. make it warmer" \
--context "send-email::revise"
The reply routes back as var="revise:<instruction>" → the Revise intercept above, which re-stages the draft for review only and never sends. Note: the email was already sent in-run (step "Send"), so this offer refines the review copy for the operator's records — any real re-send is a fresh normal invocation, not a change to the message that already went out.
-
Log to memory/logs/${today}.md:
## Send Email
- **To:** <to> (cc: <cc>)
- **Subject:** <subject>
- **Why:** <one line>
- SEND_EMAIL_SENT (or the fail-closed reason: SEND_EMAIL_SKIP/REFUSED/BLOCKED/FAILED)
If you sent the revision offer, also append - FORCE_REPLY_OFFERED: revise.