email-quality-auditor
Use when the user asks to "audit an email program" or "is this campaign safe to send"; runs a typed 20-item SEND profile with authentication, consent, opt-out, and claim veto checks on own evidence. Not for building deliverability setup — use deliverability-qa; not for designing lifecycle flows — use email-sequence-designer. 邮件质量审计/EQS评分/发送前放行
Works with
---
name: email-quality-auditor
description: Use when the user asks to "audit an email program" or "is this campaign safe to send"; runs a typed 20-item SEND profile with authentication, consent, opt-out, and claim veto checks on own evidence. Not for building deliverability setup — use deliverability-qa; not for designing lifecycle flows — use email-sequence-designer. 邮件质量审计/EQS评分/发送前放行
license: Apache-2.0
---
# Email Quality Auditor
Audit one email program/profile and observation window with SEND. Open rate is MPP-sensitive proxy evidence; direct action and the program's declared outcome truth set carry the outcome read.
## When This Must Trigger
- Before a material broadcast/sequence release when channel safety is uncertain.
- When authentication, consent, suppression, complaints, frequency, claims, or attribution need a gate.
- When the user requests an EQS/SEND baseline or rerun.
## Quick Start
```text
Audit this newsletter using the last 90 days, provider split, MPP share, and subscription truth set.
Check this promotional send against DMARC, consent events, live suppressions, claims, and order IDs.
```
## Skill Contract
**Reads:** one program/profile, normalized window, provider evidence, live consent/suppression state, rendered messages, and outcome truth. **Writes:** only a permissioned v3 artifact. **Done when:** all expected SEND states are explicit and the scorer result is reported without sending email or changing provider settings.
Use `deliverability-qa` to repair authentication, `consent-registry` for lawful-basis/suppression facts, `email-sequence-designer` for journeys, and `send-experiment-designer` for preregistered tests.
## Data Sources
| Need | Preferred evidence |
|---|---|
| Authentication | DNS, message headers, DMARC aggregate evidence |
| Consent/suppression | Append-only consent events plus current live projection |
| Placement/reputation | Provider/seed panel and dated ESP/provider reports |
| Engagement | Cohort/provider/MPP-segmented ESP export |
| Lifecycle | Trigger/flow configuration and event export |
| Outcome | Ecommerce, CRM, subscription, sponsorship, or named equivalent truth set |
| Content | Rendered message/destination and approved claim/disclosure state |
## Instructions
### Runtime Reads
- `../../../references/auditor-runbook.md`
- `../../../references/scoring-semantics.md`
- `../../../references/send-benchmark.md`
- `../../../references/runtime-invocation.md`
- `references/auditor-runtime.md`
### Runtime and Setup
Read `../../../references/auditor-runbook.md`, `scoring-semantics.md`, `send-benchmark.md`, and the SEND catalog entry. Standalone installs use bundled immutable `references/auditor-runtime.md`; never fetch mutable `main`. Before deterministic calls, follow [`runtime-invocation.md`](../../../references/runtime-invocation.md), resolve `AARON_SKILLS_ROOT="${CLAUDE_PLUGIN_ROOT:-$(git rev-parse --show-toplevel 2>/dev/null || true)}"`, and require the scorer, validator, and typed catalogs. If unavailable, return `score_state: NOT_SCORED` / `score_confidence: not_scored` with no gate verdict or persistent artifact.
Declare profile (`promotional|retention|cold-outbound|newsletter`), target/program, provider, market, normalized window, list age, MPP share, and observation date.
### Evidence and Scoring
1. Freeze evidence and reconcile provider cohorts/windows before comparing rates.
2. Score all 20 `S1..D5` criteria. Every observed state requires source/date/type/confidence.
3. `E2` is N/A with reason when opens/CTOR are not used. `N3/N5` are conditional by program design. Missing records or exports are Unknown, not N/A.
4. Verify vetoes:
- `SEND-S1`: required authentication is demonstrably broken/unaligned.
- `SEND-S2`: a purchased/scraped/unlawful list is verified; missing provenance is Unknown.
- `SEND-N1`: opt-out is broken/absent or a recorded suppression is not honored.
- `SEND-D1`: material claim/disclosure/offer term fails approved evidence.
5. Run the typed scorer. Use clicks/replies/downstream actions as primary engagement evidence where available; opens/CTOR remain caveated proxy evidence.
For a send-only review without enough program evidence, report the verified red-line checks and exact gaps but return `NOT_SCORED/UNDECIDED`; “no blocker observed in supplied evidence” is not a full SEND SHIP verdict.
## §2 SEND Worked Examples
- Complete newsletter profile, raw 81, no veto/fail: `DONE/SHIP`, final 81.
- Complete promotional profile, raw 76, one verified S1 failure: `DONE_WITH_CONCERNS/FIX`, final 59.
- Complete profile, verified S2 and N1 failures: `DONE/BLOCK`, no final score.
- Consent provenance absent: S2 Unknown, `NEEDS_INPUT/UNDECIDED`, no score.
## §3 SEND Guardrails
- DMARC `p=none` with aligned SPF/DKIM and active monitoring is not automatically an S1 failure.
- Provider one-click-unsubscribe policy and statutory duties must be named separately.
- Opens and CTOR require MPP segmentation/proxy caveat; they cannot establish human attention alone.
- A newsletter need not have cart/post-purchase flows; score only journeys applicable to its declared program.
- Over-frequency is a serious E4/E5 finding, not an automatic veto.
## §5 SEND Translation
Explain channel and recipient risk in plain language. On trace request, qualify `SEND-S1/S2/N1/D1` and show the underlying DNS/event/rendered evidence.
## Report and Verdict
Begin with the auditor-runbook's exact typed conversation header. Never replace `status`, `verdict`, or `score_state` with prose; list each explicitly missing qualified item as ``ID: `unknown``` before findings.
Show verdict, profile/context, score or coverage/interval, confidence, S/E/N/D detail, outcome truth set, verified critical controls, Unknown inputs, and fix owners. Do not claim deliverability/inbox placement from DNS alone and do not execute a send.
## Validation Checkpoints
- Program/profile/provider/window/list age/market/MPP share are declared.
- Live suppression state was verified by replay, not a stale projection or pending proposal.
- All 20 states are valid; conditional N/A has a reason.
- Provider metrics and reconciled outcome truth are separated.
- No email/provider mutation occurred without separate explicit approval.
## Persistence
Persist only after explicit authorization to `memory/audits/email/YYYY-MM-DD-<topic>.md`. Preserve the scorer's orthogonal `status` and `verdict`; validate the complete v3 draft with `validate-audit-artifact.py` against the intended `--relative-path`, persist only through one full-content Write, and revalidate the target per the auditor runbook. Edit/shell/MCP mutations of the reserved sink are unsupported. Do not autonomously modify consent, claims, provider settings, or hot cache.
## Reference Materials
- [SEND benchmark](../../../references/send-benchmark.md)
- [Measurement protocol](../../../references/measurement-protocol.md)
- [Auditor runbook](../../../references/auditor-runbook.md)
- [Scoring semantics](../../../references/scoring-semantics.md)
## Next Best Skill
- **Authentication/placement:** [deliverability-qa](../../setup/deliverability-qa/SKILL.md)
- **Consent/suppression:** [consent-registry](../../../protocol/consent-registry/SKILL.md)
- **Lifecycle:** [email-sequence-designer](../../nurture/email-sequence-designer/SKILL.md)
- **Experiment:** [send-experiment-designer](../send-experiment-designer/SKILL.md)More Security skills
azure-cost
microsoft/azure-skills
Azure cost management: query costs, forecast spending, optimize to reduce waste. WHEN: \"Azure costs\", \"Azure bill\", \"cost breakdown\", \"how much am I spending\", \"forecast spending\", \"optimize costs\", \"reduce spending\", \"orphaned resources\", \"rightsize VMs\", \"cost spike\", \"reduce storage costs\", \"AKS cost\". DO NOT USE FOR: deploying resources, provisioning, diagnostics, or security audits.
entra-app-registration
microsoft/azure-skills
Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API permissions, generate service principal, MSAL example, console app auth, Entra ID setup, Azure AD authentication. DO NOT USE FOR: Key Vault secrets (use azure-keyvault-expiration-audit), general Azure resource security guidance.
azure-messaging
microsoft/azure-skills
Troubleshoot and resolve issues with Azure Messaging SDKs for Event Hubs and Service Bus. Covers connection failures, authentication errors, message processing issues, and SDK configuration problems. WHEN: event hub SDK error, service bus SDK issue, messaging connection failure, AMQP error, event processor host issue, message lock lost, message lock expired, lock renewal, lock renewal batch, send timeout, receiver disconnected, SDK troubleshooting, azure messaging SDK, event hub consumer, service bus queue issue, topic subscription error, enable logging event hub, service bus logging, eventhub python, servicebus java, eventhub javascript, servicebus dotnet, event hub checkpoint, event hub not receiving messages, service bus dead letter, batch processing lock, session lock expired, idle timeout, connection inactive, link detach, slow reconnect, session error, duplicate events, offset reset, receive batch.

