Skills deliverability-qa
πŸ“¦

deliverability-qa

v19.0.0 Content revision r2 Safe πŸ“ Filesystem accessβš™οΈ External commands🌐 Network accessπŸ”‘ Env variables

Check email deliverability before sending

Email programs can lose inbox placement because authentication, reputation, or list data is incomplete. This skill organizes supplied evidence into a pre-send deliverability report with clear gaps and next steps.

Supports: Claude Codex Code(CC)
πŸ₯‰ 77 Bronze

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "deliverability-qa" from https://skillstore.io/skills/aaron-he-zhu-deliverability-qa.md and its manifest at https://skillstore.io/api/skills/aaron-he-zhu-deliverability-qa/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "deliverability-qa". Review these SPF, DKIM, and DMARC records before my newsletter send.

Expected outcome:

  • Authentication: Partial
  • SPF and DKIM: Pass
  • DMARC: Partial because policy is p=none
  • Next step: provide a DMARC aggregate report and inbox-placement test.

Using "deliverability-qa". My seed test shows spam placement and complaints are 0.35 percent. What should I do?

Expected outcome:

  • Inbox placement: Fail
  • Spam complaints: Fail
  • Readiness: NEEDS_INPUT
  • Pause the send and investigate complaints, authentication alignment, and creative content.

Security Audit

Safe
v10 β€’ 7/26/2026 Open versioned report

Most static findings are false positives from Markdown code formatting and relative documentation links. Two documented helper invocations execute unreviewed connector scripts, and one helper receives RESEND_API_KEY; these require verification and explicit user confirmation before use.

2
Files scanned
141
Lines analyzed
3
Review items
0
False positives ignored
Capability review items (3)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
Generic API/secret keys
**Zero-dependency ESP automation (when Resend is the ESP)**: `python3 "${CLAUDE_PLUGIN_ROOT}/scripts
The Resend connector is explicitly invoked with access to RESEND_API_KEY. Secret access by an unreviewed external helper presents a credential-exposure risk.
Medium
Ruby/shell backtick execution
**Zero-dependency ESP automation (when Resend is the ESP)**: `python3 "${CLAUDE_PLUGIN_ROOT}/scripts
The skill instructs the host to execute a Python connector located under CLAUDE_PLUGIN_ROOT. The connector source is outside the two scanned files, so its behavior cannot be verified before it receives account access.
Medium
Ruby/shell backtick execution
**Zero-dependency S1 record pull (keyless, works for any ESP)**: `python3 "${CLAUDE_PLUGIN_ROOT}/scr
The skill instructs the host to run an external DNS-over-HTTPS connector with a supplied domain argument. The connector source is not in the scanned files, so input handling and network behavior cannot be verified.
Audited by: claude View Audit History β†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/aaron-he-zhu-deliverability-qa/audits/10?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/aaron-he-zhu-deliverability-qa/security.svg)](https://skillstore.io/skills/aaron-he-zhu-deliverability-qa?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/aaron-he-zhu-deliverability-qa?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/aaron-he-zhu-deliverability-qa/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/aaron-he-zhu-deliverability-qa.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA Β· BibTeX Β· CFF)

APA citation

aaron-he-zhu. (2026). deliverability-qa security audit report (audit version 10) [Author version 19.0.0]. Skillstore. https://skillstore.io/skills/aaron-he-zhu-deliverability-qa/audits/10

BibTeX citation

@techreport{aaron-he-zhu-aaron-he-zhu-deliverability-qa-2026, author = {aaron-he-zhu}, title = {deliverability-qa security audit report (audit version 10)}, institution = {Skillstore}, year = {2026}, number = {10}, url = {https://skillstore.io/skills/aaron-he-zhu-deliverability-qa/audits/10}, note = {Author version 19.0.0} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "deliverability-qa security audit report (audit version 10)" version: "19.0.0" type: report authors: - name: "aaron-he-zhu" date-released: "2026-07-26" url: "https://skillstore.io/skills/aaron-he-zhu-deliverability-qa/audits/10" identifiers: - type: other value: "skillstore:aaron-he-zhu-deliverability-qa:audit:10" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
41
Architecture
100
Maintainability
87
Content
67
Community
91
Spec Compliance

What You Can Build

Pre-send campaign review

Check authentication and inbox-placement evidence before a marketing campaign launches.

New sending-domain validation

Identify missing SPF, DKIM, DMARC, or BIMI evidence during a domain setup.

Deliverability incident triage

Organize reputation, complaint, bounce, and creative evidence after spam-folder placement.

Try These Prompts

Start a basic pre-flight
Run a deliverability pre-flight for my sending domain. Tell me which evidence you need first.
Check authentication records
Review these SPF, DKIM, DMARC, and BIMI records for example.com. Mark each item Pass, Partial, Fail, or Unknown.
Assess a campaign
Review my DMARC report, inbox-placement test, ESP bounce and complaint rates, and email HTML. Give me a pre-send checklist.
Create a readiness handoff
Using this deliverability evidence for a promotional program, produce a complete SEND-S summary. List missing evidence and do not score incomplete items.

Best Practices

  • Provide current DNS records, a DMARC aggregate report, and a seed-list test together.
  • Use evidence from the same sending domain and campaign period.
  • Treat Unknown items as evidence gaps instead of passing them by default.

Avoid

  • Do not score readiness when required evidence is missing.
  • Do not treat a DNS record as proof that messages pass authentication.
  • Do not use this one-time review as a replacement for ongoing list monitoring.

Frequently Asked Questions

What evidence should I provide?
Provide DNS records, a DMARC aggregate report, inbox-placement results, and an ESP deliverability report when available.
Does this skill send email?
No. It reviews evidence and prepares a pre-send readiness report.
Can it check SPF, DKIM, and DMARC?
Yes. It reviews supplied records and DMARC evidence for presence, alignment, and reported passing status.
Does it make the final send decision?
No. It flags S1 evidence and prepares a SEND-S summary for the email quality auditor.
Can it monitor bounce rates over time?
No. It reads a point-in-time snapshot. Use a dedicated hygiene monitor for recurring trends.
Are connector commands required?
No. The skill supports manual exports and keyless checks. Review and approve any connector command before running it.

Developer Details

License

Apache-2.0

Author version

v19.0.0

Skillstore revision

r2

Ref

adcb3549b15782055d0beb6d29f113d20de08f92

Maintenance freshness

7/28/2026

Usage

3 downloads Β· 1 views

File structure

More from aaron-he-zhu

View all
View all