Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Sms Pro

ASecurity

Use SMS professionally — business texting etiquette, alerts, 2FA-adjacent flows, and compliant organizational messaging.

2 stars
0 votes
0 copies
0 views
Added 9/29/2026
ai-agentsgogitapisecurityperformance

Works with

api

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add aicodedecode/awesome-muse-skills --skill sms-pro --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Sms Pro?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Sms Pro
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-sms-pro/badge)](https://www.skillsdirectory.com/skills/aicodedecode-sms-pro)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: sms-pro
description: Use SMS professionally — business texting etiquette, alerts, 2FA-adjacent flows, and compliant organizational messaging.
category: enterprise-communication
---

## Overview

SMS in professional contexts means transactional and operational messaging: alerts, reminders, coordination, and time-sensitive notifications — not marketing blasts (see sms-marketer for that). This skill covers business texting: etiquette, alert design, automation, and the compliance basics for organizational SMS.


Professional SMS — appointment reminders, delivery updates, authentication codes, urgent alerts — reaches people faster than any other channel: 90%+ read within minutes. That speed makes it ideal for time-critical operational messaging and terrible for anything that can wait. The skill is reserving SMS for moments where immediacy genuinely matters.
## When to use

- Setting up operational SMS alerts
- Writing appointment/service reminders
- Coordinating teams via text
- Designing notification SMS (deliveries, incidents, system alerts)
- Establishing business texting policies
- Choosing SMS for internal vs. external comms

- Appointment reminders and confirmations
- Two-factor authentication and security alerts
- Urgent operational notifications (outages, delays)
- Implementing SMS APIs for developers
- Building international SMS coverage
- Choosing SMS providers
## Core concepts

**SMS role in the mix.** SMS is for: time-sensitive alerts, reminders, short coordination, and 2FA/verification codes. It's not for: long discussions (use email/chat), sensitive data (use secure channels), or anything non-urgent (respect the interruption).

**Alert design.** Critical alerts: what happened, impact, what to do, where to go — in 160 characters. Include severity, avoid jargon, link to details. Alert fatigue is real: only truly actionable items via SMS; everything else via less intrusive channels.

**Reminders.** Appointment/service reminders: who, what, when, where, how to confirm/cancel/reschedule. Send at useful intervals (24h + 2h typical). Two-way (reply C to confirm) dramatically reduces no-shows.

**Business texting etiquette.** Identify yourself/organization, keep it brief, respect hours (no non-urgent texts outside business hours), one topic per message, and provide an opt-out path. Professional tone — texts feel personal, so sloppiness stands out.

**Automation.** Triggered SMS from systems: monitoring alerts, scheduling systems, delivery updates, incident notifications. Build in: deduplication (don't send the same alert 50 times), escalation (unacknowledged → next person), and quiet hours with critical-override rules.

**Compliance basics.** Consent for non-transactional messages, opt-out honoring (STOP), sender identification, and data retention policies. Transactional messages (alerts the user signed up for) have lighter requirements than promotional — but document consent either way. Consult legal for your jurisdiction.


**Transactional vs. promotional.** Transactional SMS (order updates, codes, alerts) enjoys high tolerance because it is expected and useful. Promotional SMS faces strict consent requirements and low tolerance. Never blur the line — sending marketing in transactional streams triggers complaints and regulatory risk.

**Sender identity.** Short codes (5–6 digits, high throughput, expensive), long codes / 10DLC (standard numbers, conversational, US carrier-registered), and alphanumeric sender IDs (international, one-way). Choose by use case: 10DLC for conversational business texting, short codes for high-volume alerts, toll-free for support lines.

**Quiet hours and frequency.** Even transactional messages respect local quiet hours (typically 8am–9pm). Frequency expectations: authentication = instant, appointments = 24h + 2h reminders, alerts = only when actionable. Every unnecessary text trains recipients to ignore the necessary ones.

**Provider selection.** Evaluate: delivery rates by country, latency, pricing (per-segment, not per-message — segments matter), API quality, support responsiveness, and compliance features.
Test with real traffic before committing — provider performance varies enormously by destination.
Multi-provider setups hedge outages but add complexity.
**Encoding and segmentation.** GSM-7 (160 chars/segment) vs. Unicode (70 chars/segment) — emojis and non-Latin scripts triple costs.
Concatenate carefully; long messages cost multiples.
Character counters in composing UIs prevent surprise bills.
**Delivery monitoring.** Delivery receipts (DLRs), latency tracking, failure categorization (invalid number, carrier block, content filter), and retry logic.
Monitor by destination — country-level issues hide in global averages.
Alert on delivery drops; they indicate blocks or outages.
## Practical workflow

1. **Define use cases.** List what merits SMS: incident alerts, appointment reminders, delivery notifications, shift coordination, verification codes. Everything else uses other channels.
2. **Design message templates.** Per use case: concise template with variables, severity levels for alerts, and clear CTAs. Test readability — if it needs scrolling, it's too long.
3. **Set policies.** Quiet hours, opt-in/opt-out handling, who can send broadcast texts, tone guidelines, and data retention. Publish the policy.
4. **Build automation.** Integrate with source systems (monitoring, scheduling, ticketing). Implement: dedup, escalation chains, acknowledgment tracking, and delivery logging.
5. **Launch carefully.** Start with transactional use cases (lowest risk, highest value). Monitor: delivery rates, opt-out rates, response times, and complaint feedback.
6. **Review.** Monthly: are alerts actionable? (If routinely ignored, they're noise — fix or remove.) Opt-out trends, after-hours volume, and user feedback.

**Incident alert template:** "[SEV2] Payment API error rate 15% (threshold 5%). Dashboard: [link]. Ack: reply ACK. On-call: [name]."


**Appointment reminder sequence:** T-48h: confirmation request (reply YES to confirm) → T-24h: reminder with details (time, location, preparation) → T-2h: final nudge with check-in link. No-show rates typically drop 30–50% with this sequence. Include reschedule links — friction-free rescheduling beats no-shows.

**2FA SMS best practices:** 6-digit codes (memorable, auto-fillable) → 5–10 minute expiry → clear sender identification → "never share this code" warning → rate-limit requests (prevent SMS bombing) → offer authenticator-app alternatives. Monitor delivery rates by carrier — SMS 2FA fails silently on some networks.

**API integration checklist:** credentials secured → webhook endpoints for DLRs → retry logic with backoff → number validation pre-send → opt-out list syncing → rate limiting → test numbers across carriers → monitoring dashboards.
Load-test before campaigns — provider rate limits surprise the unprepared.
**Cost optimization:** validate numbers (remove landlines, invalid) → use correct encoding → batch where possible → negotiate volume pricing → monitor per-campaign costs.
SMS costs scale linearly — 10% waste reduction is real money at volume.
## Common pitfalls

- **Alert fatigue.** SMS for everything means SMS for nothing. Reserve for actionable and urgent.
- **No dedup.** 47 identical alerts at 3am. Deduplicate and escalate instead.
- **After-hours non-urgent texts.** Respect quiet hours; use scheduled sends for morning delivery.
- **Missing opt-out.** No way to stop messages. Always provide and honor opt-out.
- **Sensitive data via SMS.** Passwords, full account numbers, health details — SMS isn't secure. Use it for pointers, not payloads.
- **No acknowledgment tracking.** Sending critical alerts into the void. Track acks; escalate silence.
- **Inconsistent sender identity.** Messages from random numbers. Use consistent, identified sender IDs.
- **Using SMS for non-urgent content.** Newsletters via text. Reserve SMS for immediacy — everything else belongs in email or push.
- **No opt-out handling.** Failing to process STOP requests immediately. Regulatory penalties are severe and per-message.
- **Ignoring international complexity.** Sender ID rules, character encoding (GSM vs. Unicode segment limits), and pricing vary wildly by country. Test per market.
- **No DLR handling.** Sending blind without delivery confirmation. DLRs are the only truth about delivery — process them.
- **Single provider dependency.** Provider outages halt all messaging. Critical flows deserve failover providers.

Attribution

aicodedecodeaicodedecode
View sourceSee grades on GitHubMore from aicodedecode →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698431 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →