agentsclimarketplace

Email quality auditor

Skill aiskillstore/marketplace/skills/aaron-he-zhu/email-quality-auditor

Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified.

Install
npx -y skills add aiskillstore/marketplace --skill email-quality-auditor

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.

What its author says it does

Copied from the file, not written here

Use when the user asks to "audit an email program" or "is this campaign safe to send"; runs a typed 20-item SEND profile with authentication, consent, opt-out, and claim veto checks on own evidence. Not for building deliverability setup — use deliverability-qa; not for designing lifecycle flows — use email-sequence-designer. 邮件质量审计/EQS评分/发送前放行

The file declares its own license as Apache-2.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

8.0 KB, as published. Nobody here has run it

Email Quality Auditor

Audit one email program/profile and observation window with SEND. Open rate is MPP-sensitive proxy evidence; direct action and the program's declared outcome truth set carry the outcome read.

When This Must Trigger

  • Before a material broadcast/sequence release when channel safety is uncertain.
  • When authentication, consent, suppression, complaints, frequency, claims, or attribution need a gate.
  • When the user requests an EQS/SEND baseline or rerun.

Quick Start

Audit this newsletter using the last 90 days, provider split, MPP share, and subscription truth set.
Check this promotional send against DMARC, consent events, live suppressions, claims, and order IDs.

Skill Contract

Reads: one program/profile, normalized window, provider evidence, live consent/suppression state, rendered messages, and outcome truth. Writes: only a permissioned v3 artifact. Done when: all expected SEND states are explicit and the scorer result is reported without sending email or changing provider settings.

Use deliverability-qa to repair authentication, consent-registry for lawful-basis/suppression facts, email-sequence-designer for journeys, and send-experiment-designer for preregistered tests.

Data Sources

NeedPreferred evidence
AuthenticationDNS, message headers, DMARC aggregate evidence
Consent/suppressionAppend-only consent events plus current live projection
Placement/reputationProvider/seed panel and dated ESP/provider reports
EngagementCohort/provider/MPP-segmented ESP export
LifecycleTrigger/flow configuration and event export
OutcomeEcommerce, CRM, subscription, sponsorship, or named equivalent truth set
ContentRendered message/destination and approved claim/disclosure state

Instructions

Runtime and Setup

Read ../../../references/auditor-runbook.md, scoring-semantics.md, send-benchmark.md, and the SEND catalog entry. Standalone installs use bundled immutable references/auditor-runtime.md; never fetch mutable main. Before deterministic calls, follow runtime-invocation.md, resolve AARON_SKILLS_ROOT="${CLAUDE_PLUGIN_ROOT:-$(git rev-parse --show-toplevel 2>/dev/null || true)}", and require the scorer, validator, and typed catalogs. If unavailable, return score_state: NOT_SCORED / score_confidence: not_scored with no gate verdict or persistent artifact.

Declare profile (promotional|retention|cold-outbound|newsletter), target/program, provider, market, normalized window, list age, MPP share, and observation date.

Evidence and Scoring

  1. Freeze evidence and reconcile provider cohorts/windows before comparing rates.
  2. Score all 20 S1..D5 criteria. Every observed state requires source/date/type/confidence.
  3. E2 is N/A with reason when opens/CTOR are not used. N3/N5 are conditional by program design. Missing records or exports are Unknown, not N/A.
  4. Verify vetoes:
    • SEND-S1: required authentication is demonstrably broken/unaligned.
    • SEND-S2: a purchased/scraped/unlawful list is verified; missing provenance is Unknown.
    • SEND-N1: opt-out is broken/absent or a recorded suppression is not honored.
    • SEND-D1: material claim/disclosure/offer term fails approved evidence.
  5. Run the typed scorer. Use clicks/replies/downstream actions as primary engagement evidence where available; opens/CTOR remain caveated proxy evidence.

For a send-only review without enough program evidence, report the verified red-line checks and exact gaps but return NOT_SCORED/UNDECIDED; “no blocker observed in supplied evidence” is not a full SEND SHIP verdict.

§2 SEND Worked Examples

  • Complete newsletter profile, raw 81, no veto/fail: DONE/SHIP, final 81.
  • Complete promotional profile, raw 76, one verified S1 failure: DONE_WITH_CONCERNS/FIX, final 59.
  • Complete profile, verified S2 and N1 failures: DONE/BLOCK, no final score.
  • Consent provenance absent: S2 Unknown, NEEDS_INPUT/UNDECIDED, no score.

§3 SEND Guardrails

  • DMARC p=none with aligned SPF/DKIM and active monitoring is not automatically an S1 failure.
  • Provider one-click-unsubscribe policy and statutory duties must be named separately.
  • Opens and CTOR require MPP segmentation/proxy caveat; they cannot establish human attention alone.
  • A newsletter need not have cart/post-purchase flows; score only journeys applicable to its declared program.
  • Over-frequency is a serious E4/E5 finding, not an automatic veto.

§5 SEND Translation

Explain channel and recipient risk in plain language. On trace request, qualify SEND-S1/S2/N1/D1 and show the underlying DNS/event/rendered evidence.

Report and Verdict

Begin with the auditor-runbook's exact typed conversation header. Never replace status, verdict, or score_state with prose; list each explicitly missing qualified item as ``ID: `unknown``` before findings.

Show verdict, profile/context, score or coverage/interval, confidence, S/E/N/D detail, outcome truth set, verified critical controls, Unknown inputs, and fix owners. Do not claim deliverability/inbox placement from DNS alone and do not execute a send.

Validation Checkpoints

  • Program/profile/provider/window/list age/market/MPP share are declared.
  • Live suppression state was verified by replay, not a stale projection or pending proposal.
  • All 20 states are valid; conditional N/A has a reason.
  • Provider metrics and reconciled outcome truth are separated.
  • No email/provider mutation occurred without separate explicit approval.

Persistence

Persist only after explicit authorization to memory/audits/email/YYYY-MM-DD-<topic>.md. Preserve the scorer's orthogonal status and verdict; validate the complete v3 draft with validate-audit-artifact.py against the intended --relative-path, persist only through one full-content Write, and revalidate the target per the auditor runbook. Edit/shell/MCP mutations of the reserved sink are unsupported. Do not autonomously modify consent, claims, provider settings, or hot cache.

Reference Materials

Next Best Skill

Gives 0 of the 12 instructions most audit compliance skills give

Counted across 936 of the 1,487 authors here whose files we hold, read 2026-08-06

  • group findings by severityin 44 of 936
  • Fetch latest guidelines before each reviewin 43 of 936, across 3 files
  • Check files against all fetched rulesin 42 of 936, across 2 files
  • Output findings in terse file:line formatin 41 of 936, across 3 files
  • Ask user which files to review if none specifiedin 41 of 936, across 3 files
  • Read specified files or prompt user for filesin 39 of 936, across 1 file
  • generate the audit reportin 39 of 936, across 36 files
  • assign a severity to every findingin 25 of 936
  • run automated accessibility scansin 23 of 936, across 13 files
  • map findings to WCAG criteriain 20 of 936, across 10 files
  • confirm audit scopein 19 of 936, across 9 files
  • check title tags and meta descriptions for uniquenessin 19 of 936, across 5 files

Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.