SKILLS/onboarding-optimization/SKILL.md
When the user wants to improve their app's onboarding experience, increase activation rate, reduce Day 1 drop-off, or optimize the first-run flow. Use when the user mentions "onboarding", "first-run", "activation", "tutorial", "day 1 retention", "new user flow", "permission prompts", "sign-up conversion", "onboarding funnel", or "users dropping off early". For overall retention strategy, see retention-optimization. For paywall placement, see monetization-strategy.
npx skillsauth add pinkpixel-dev/skills-collection-2 onboarding-optimizationInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
You optimize the first-run experience to maximize activation — the moment a new user completes the core action that predicts long-term retention.
Activation ≠ sign-up. Activation is the first time the user gets real value from your app. Identify it before anything else.
| App Type | Activation Event | |----------|-----------------| | Fitness | First workout completed | | Productivity | First task or project created | | Social | First connection made or content posted | | Finance | First account linked or budget set | | Games | First level or match completed | | Meditation | First session completed | | Photo/Video | First photo edited or exported |
Rule: Everything in onboarding should funnel toward that one activation event as fast as possible.
app-marketing-context.mdList every screen from app open to activation:
App open → [Screen 1] → [Screen 2] → ... → Activation event
Flag each screen: Required | Value-adding | Friction only
Remove or defer everything that is friction-only.
| Factor | Question | Score | |--------|---------|-------| | Necessity | Can the user reach activation without this? | 0 = skip it | | Timing | Is this the right moment for this ask? | | | Value exchange | Does the user understand why this benefits them? | | | Cognitive load | How many decisions does this require? | |
Permissions are the #1 drop-off point. Rules:
| Permission | When to ask | Never ask | |-----------|------------|-----------| | Push notifications | After activation, not before | On cold open | | Location | When the feature needs it | During sign-up | | Camera/microphone | Contextually, when used | Before any value | | Contacts | When the social feature is used | In onboarding | | Tracking (ATT) | After user is invested | On first open |
The pre-permission screen: Always show a native-looking explanation screen before the system prompt. Users who understand the "why" grant at 2–3× the rate.
| Pattern | Impact | Recommendation | |---------|--------|---------------| | Required sign-up before value | High drop-off | Defer to post-activation | | Only email+password | Medium drop-off | Add Sign in with Apple + Google | | Long profile setup | High drop-off | Ask 1 question max, defer rest | | Email verification required | Kills momentum | Defer or make optional |
Guest mode / try before sign-up: Allow users to experience the core value before requiring an account. Conversion from guest → registered is typically 40–60% vs. a hard gate at 15–30%.
Open → Core feature demo / interactive preview
→ Activation moment
→ "Save your progress" → Sign-up
→ Permission asks
→ Personalization
Open → 3–5 personalization questions (show progress bar)
→ "Your plan is ready" reveal moment
→ Sign-up gate (invested now)
→ Activation
Open → Sign in with Apple/Google (single tap)
→ Find friends / follow suggestions
→ First feed with content
→ Activation (post, comment, react)
| Step | Benchmark | Poor | |------|-----------|------| | App open → first interaction | > 85% | < 70% | | Sign-up conversion | > 60% | < 40% | | Push permission grant | > 50% | < 30% | | Activation (D0) | > 40% | < 20% | | Day 1 retention | > 30% | < 15% |
If you include personalization, follow these rules:
Rule: Show value before the paywall.
| Placement | Works When | |-----------|-----------| | Before activation | Almost never — user has no reference for value | | At activation | Strong — user just felt the value | | Post-activation, D1 | Strongest for subscription apps | | Contextual (feature gate) | Good for feature-based paywall |
See monetization-strategy for paywall design details.
Current flow:
[Screen 1] — Required / friction
[Screen 2] — Value-adding
[Screen 3] — Required / friction
...
[Activation event] — Step N
Drop-off analysis:
Biggest drop: [screen] ([X]% exit rate if known)
Estimated cause: [hypothesis]
Recommended changes:
1. [Remove / defer X] — Expected impact: [lift in activation]
2. [Reorder Y before Z] — Expected impact: [rationale]
3. [Add pre-permission screen for Z] — Expected impact: [grant rate improvement]
Revised flow:
Open → [Screen] → [Screen] → Activation → Sign-up → Permissions
Estimated steps removed: [N]
Estimated time to activation: [Xs → Xs]
[Icon representing the permission]
[Benefit headline — what the user gets]
e.g., "Get notified when your goal is complete"
[One-line explanation]
e.g., "We'll only send you reminders you set — no spam."
[Allow button] [Not now]
retention-optimization — Day 7/30 retention strategymonetization-strategy — Paywall placement and trial designab-test-store-listing — Test onboarding variantsapp-analytics — Set up activation funnel trackingrating-prompt-strategy — When to ask for a rating post-activationdevelopment
A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardco
tools
Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations.
testing
Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations, JSONP endpoints, unsafe directives, and policy injection techniques.
testing
Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.