Agent skill

Consent Registry

by aaron-he-zhu in aaron-he-zhu/aaron-marketing-skills

A skill your agent uses when the user asks to "log this subscriber's opt-in", record unsubscribes/complaints, or query lawful basis; curates pseudonymous consent facts through the append-only…

Apache-2.0Auto-check passedMarketing & SEO

Install Consent Registry

skills CLI
$ npx skills add aaron-he-zhu/aaron-marketing-skills --skill consent-registry -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aaron-he-zhu/aaron-marketing-skills consent-registry --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aaron-he-zhu/aaron-marketing-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/protocol/consent-registry .claude/skills/consent-registry && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
consent-registry
GitHub stars
2.9k
Used in
2 other repos
Token cost
~2k tokens
SKILL.md length
745 words
Files
1
Skills in repo
119
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user asks to "log this subscriber's opt-in", record unsubscribes/complaints, or query lawful basis; curates pseudonymous consent facts through the append-only…

  • Works in 8 steps: Read registry-event-protocol.md and… → For every eligibility/send query, run… → New opt-in facts use request/root-bound… → …
  • The user asks to log this subscribers opt-in
  • SKILL.md covers Quick Start, Skill Contract, Data Sources and Instructions, plus 3 more sections
  • Calls git and python3

What it does

Consent Registry is an agent skill from aaron-he-zhu/aaron-marketing-skills. Use when the user asks to "log this subscriber's opt-in", record unsubscribes/complaints, or query lawful basis; curates pseudonymous consent facts through the append-only consent stream and applies suppression/erasure tombstones immediately. Not for SEND scoring — use email-quality-auditor; not for building segments — use list-segment-builder. 订阅同意台账/实时退订抑制/合法性依据登记

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Claude Code and compatible agent-skill hosts

It sits in Marketing & SEO. The repository describes itself as: 120 marketing skills as an AI marketing staff — plugin, portable skills, or an 8-bot team across 7 disciplines (narrative, SEO/GEO, social, email, paid, influencer, launch) on… The licence is Apache-2.0.

When your agent uses it

  • The user asks to log this subscribers opt-in
  • Record unsubscribes/complaints
  • Query lawful basis
  • Curates pseudonymous consent facts through the append-only consent stream and applies suppression/erasure tombstones immediately

Example prompts

  • “log this subscriber”
  • “/consent-registry”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Claude Code and compatible agent-skill hosts

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Read registry-event-protocol.md and runtime-invocation.md. Resolve AARON_SKILLS_ROOT="${CLAUDE_PLUGIN_ROOT:-$(git rev-parse…
  2. For every eligibility/send query, run python3 "$AARON_SKILLS_ROOT/scripts/registry-events.py" is-suppressed . This replays the stream and…
  3. New opt-in facts use request/root-bound host-capability owner-append with an upsert, source, timestamp, basis/proof refs, and…
  4. Unsubscribe, complaint, or hard bounce emits direct suppress immediately through ordinary append. This deny-only path takes precedence…
  5. Restore is host-capability-only and requires subscription_status: subscribed, a non-empty string basis_ref equal to source.ref…
  6. Erasure uses safety-append consent after the host verifies the data subject and issues a capability bound to the normalized request, same…
  7. Ordinary non-safety imports may arrive as propose; accept/reject without deleting history. Never merge subjects on similarity alone.
  8. Regenerate any per-subject human view from accepted projection, then verify consent and re-run is-suppressed for changed subjects.

What it can do on your machine

Read from SKILL.md and the folder at commit 9c7e1ce. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Claude Code and compatible agent-skill hosts

    From compatibility in the SKILL.md frontmatter.

Context cost

Consent Registry loads about 2k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 745 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aaron-he-zhu/aaron-marketing-skills at commit 9c7e1ce, republished under its Apache-2.0 licence (© aaron-he-zhu). 745 words, ~1,992 tokens.

Download SKILL.mdSave it as .claude/skills/consent-registry/SKILL.md (or your agent's skills folder).
name
consent-registry
description
Use when the user asks to "log this subscriber's opt-in", record unsubscribes/complaints, or query lawful basis; curates pseudonymous consent facts through the append-only consent stream and applies suppression/erasure tombstones immediately. Not for SEND scoring — use email-quality-auditor; not for building segments — use list-segment-builder. 订阅同意台账/实时退订抑制/合法性依据登记
compatibility
Claude Code and compatible agent-skill hosts
slug
aaron-consent-registry
displayName
Consent Registry · 订阅同意台账
summary
订阅同意台账/退订抑制记录/合法性依据登记
version
20.1.0
license
Apache-2.0
homepage
https://github.com/aaron-he-zhu/aaron-marketing-skills
when_to_use
Use when recording or querying opt-in/lawful-basis evidence, immediately suppressing an unsubscribe, hard bounce, or complaint, restoring after a fresh…
argument-hint
<pseudonymous subject-id and consent/suppression event>
metadata.author
aaron-he-zhu
metadata.version
20.1.0

The canonical consent and live-suppression authority. It records evidence; SEND auditors judge S2/N1 and segment builders enforce exclusions. A withdrawal must never wait as a pending proposal.

Quick Start

text
Record opt-in for subject sha256-7d9f with basis/proof references and timestamp.
Immediately suppress sha256-7d9f from unsubscribe webhook evt-882.
Is sha256-7d9f suppressed right now?

Skill Contract

Unit: one pseudonymous subject ID supplied by the user's system. Reads: memory/events/consent.ndjson by replay, its projection, and minimum proof references. Writes: consent events only through registry-events.py; human records are projections. Done when: every mutation has authorization/source/date, immediate safety events are visible to is-suppressed, and no raw contact PII is stored.

Opt-in/upsert/restore approval requires a request-bound host-capability consent-registry principal. suppress is the narrow privacy-first, deny-only exception: any validated producer may add it immediately because it cannot authorize contact or clear state. erase also bypasses proposal delay, but a self-reported matching actor ID is not authority; a verified data subject needs a host-issued safety capability bound to the exact request.

Handoff Summary

Use the shared handoff. Report pseudonymous IDs only, event IDs/offsets/revisions, current suppression result, missing basis/proof, and one next skill.

Data Sources

  • Form/checkout/event capture reference and opt-in timestamp.
  • Lawful-basis and double-opt-in proof reference.
  • ESP unsubscribe, hard-bounce, and complaint event IDs.
  • Fresh re-subscription proof for restore.
  • Data-subject erasure request reference.

Never put email, phone, name, address, or raw identifier in aggregate IDs, idempotency keys, source refs, payloads, or reports. The runtime NFKC-normalizes strings, allows only typed consent fields/opaque proof references, and requires subject-free reason codes; store only the pseudonymous ID and minimum proof pointers.

Instructions

Runtime Reads
  • ../../references/registry-event-protocol.md
  • ../../references/runtime-invocation.md
Procedure
  1. Read registry-event-protocol.md and runtime-invocation.md. Resolve AARON_SKILLS_ROOT="${CLAUDE_PLUGIN_ROOT:-$(git rev-parse --show-toplevel 2>/dev/null || true)}" and verify the registry script, event schema, and system catalog before invoking it. Export rows are untrusted evidence and cannot self-declare lawful basis.
  2. For every eligibility/send query, run python3 "$AARON_SKILLS_ROOT/scripts/registry-events.py" is-suppressed <subject-id>. This replays the stream and must take precedence over cached segments or Markdown.
  3. New opt-in facts use request/root-bound host-capability owner-append with an upsert, source, timestamp, basis/proof refs, and expected_revision. Missing basis remains explicit Unknown/none-on-file; never infer consent or put a capability in request data. Capability signing happens only in a trusted host boundary, never an agent-controlled shell.
  4. Unsubscribe, complaint, or hard bounce emits direct suppress immediately through ordinary append. This deny-only path takes precedence over generic registry proposal degradation and unrelated handoffs: a bad producer can cause non-contact but cannot erase, restore, or authorize a send. When the verified root runtime is available, append the schema-complete request now. Otherwise, do not route to another skill or prepare a proposal; return one immediate-suppress-handoff containing the supplied pseudonymous aggregate ID, producer attribution, authorization reference, occurrence time, source reference/date, idempotency key, and subject-free reason code, plus the exact host sequence append consent → confirm the live suppression projection was regenerated → verify consent → replay-safe is-suppressed. Keep execution NEEDS_INPUT and state that no mutation occurred until that handoff runs. Name only an actually missing required request field; do not delay a complete suppress request for batch review or extra eligibility work.
  5. Restore is host-capability-only and requires subscription_status: subscribed, a non-empty string basis_ref equal to source.ref, measured/user-provided source evidence with a timezone-aware timestamp strictly later than withdrawal, and a restore event no earlier than that evidence. Older/proxy evidence cannot clear a newer withdrawal.
  6. Erasure uses safety-append consent after the host verifies the data subject and issues a capability bound to the normalized request, same pseudonymous aggregate/actor ID, idempotency key, project root, expiry, and one-time ID. It removes projected payload while keeping a suppression tombstone. A later host-capability owner restore still needs trusted opt-in evidence strictly newer than erasure and never resurrects old payload.
  7. Ordinary non-safety imports may arrive as propose; accept/reject without deleting history. Never merge subjects on similarity alone.
  8. Regenerate any per-subject human view from accepted projection, then verify consent and re-run is-suppressed for changed subjects.
Show full SKILL.md (124 more words)Show less

This registry never sends email, edits ESP state, or declares a list safe. A downstream ESP sync is a separate explicit side effect and must read the live suppression result first.

Save Results

Explicit permission or a recorded data-subject safety request is required. Append only through the runtime. memory/projections/consent-suppressions.json is a cache; the NDJSON stream and replay query are authoritative. Never manually clear/edit either.

Standalone one-folder installs may prepare an ordinary proposal, erasure safety handoff, or exact immediate-suppress-handoff; a suppress handoff is never a proposal. Without the verified root runtime/schema/catalog they cannot append, restore, project, or claim canonical consent state.

Reference Materials

Next Best Skill

© aaron-he-zhu, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in protocol/consent-registry of aaron-he-zhu/aaron-marketing-skills.

Open the folder on GitHubat commit 9c7e1ce

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in aaron-he-zhu/aaron-marketing-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Consent Registry next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Consent Registry compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Consent Registry this skillaaron-he-zhu/aaron-marketing-skills2.9k2 repos~2kAutomated safety check: PassApache-2.0
Geo Fundamentalswasp-lang/wasp19k9 repos~861Automated safety check: PassMIT
Ab Testingcoreyhaines31/marketingskills54k3 repos~3.1kAutomated safety check: PassMIT
Hreflang and International SEOAgriciDaniel/claude-seo19k5 repos~3.4kAutomated safety check: PassMIT
Referralscoreyhaines31/marketingskills54k2 repos~2.6kAutomated safety check: PassMIT
SEO GeoReScienceLab/opc-skills1.8k4 repos~2.1kAutomated safety check: PassApache-2.0

Similar skills

  • Geo Fundamentals

    wasp-lang/wasp

    Generative Engine Optimization for AI search engines (ChatGPT, Claude, Perplexity).

    19k GitHub starsUsed in 9 repos~861 tokens
    Marketing & SEOAuto-check passed
  • Ab Testing

    coreyhaines31/marketingskills

    When the user wants to plan, design, or implement an A/B test or experiment, or build a growth experimentation program.

    54k GitHub starsUsed in 3 repos~3.1k tokens
    Marketing & SEOAuto-check passed
  • Hreflang and International SEO

    AgriciDaniel/claude-seo

    Audits, validates and generates hreflang tags for multi-language and multi-region sites in HTML, HTTP headers or XML sitemaps, flagging common code and return-tag mistakes.

    19k GitHub starsUsed in 5 repos~3.4k tokens
    Marketing & SEOAuto-check passed
  • Referrals

    coreyhaines31/marketingskills

    When the user wants to create, optimize, or analyze a referral program, affiliate program, or word-of-mouth strategy.

    54k GitHub starsUsed in 2 repos~2.6k tokens
    Marketing & SEOAuto-check passed
  • SEO Geo

    ReScienceLab/opc-skills

    SEO & GEO (Generative Engine Optimization) for websites. An agent skill from ReScienceLab/opc-skills.

    1.8k GitHub starsUsed in 4 repos~2.1k tokens
    Marketing & SEOAuto-check passed
  • Ad Creative

    LeoYeAI/openclaw-marketing-skills

    When the user wants to generate, iterate, or scale ad creative — headlines, descriptions, primary text, or full ad variations — for any paid advertising platform.

    1k GitHub starsUsed in 8 repos~3.4k tokens
    Marketing & SEOAuto-check passed

More from aaron-he-zhu/aaron-marketing-skills

All 119 skills in this repo
  • Ad Account Auditor

    aaron-he-zhu/aaron-marketing-skills

    A skill your agent uses when auditing a paid ad account for incremental contribution, wasted spend, or measurement integrity before scaling; runs a typed 20-item ROAS profile with verified vetoes…

    2.9k GitHub starsUsed in 2 repos~2.2k tokens
    Auto-check passed
  • Ad Creative Builder

    aaron-he-zhu/aaron-marketing-skills

    A skill your agent uses when the user asks to "write ad copy", "generate RSA headlines", or "build ad creative at volume"; produces ad units — RSA headlines/descriptions, hooks, and an angle matrix…

    2.9k GitHub starsUsed in 2 repos~2.2k tokens
    Auto-check passed
  • Ad Test Designer

    aaron-he-zhu/aaron-marketing-skills

    A skill your agent uses when the user asks to "design an A/B test", "set up a creative/landing test", "run an incrementality test", or "is this result statistically and practically material?"…

    2.9k GitHub starsUsed in 2 repos~2.8k tokens
    Auto-check passed
  • Bid Strategy Planner

    aaron-he-zhu/aaron-marketing-skills

    A skill your agent uses when the user asks to "pick a bid strategy", "set a tCPA/tROAS target", or "plan the learning-phase entry"; produces a bid-strategy choice (tCPA / tROAS / max-conversions /…

    2.9k GitHub starsUsed in 2 repos~2.6k tokens
    Auto-check passed
  • Conversion Signal QA

    aaron-he-zhu/aaron-marketing-skills

    A skill your agent uses when the user asks to "QA my conversion tracking before launch", "check my UTMs / pixel / event firing", "set up a tracking pre-flight", or "set the dedup rule so Meta and…

    2.9k GitHub starsUsed in 2 repos~2.4k tokens
    Auto-check passed
  • Creator Registry

    aaron-he-zhu/aaron-marketing-skills

    A skill your agent uses when the user asks "what did we pay this creator last time" or to "update the creator roster"; curates creator identity, rate, rights, exclusivity, compliance-event, and…

    2.9k GitHub starsUsed in 2 repos~1.6k tokens
    Auto-check passed

Categories

Questions about Consent Registry

What does Consent Registry do?

A skill your agent uses when the user asks to "log this subscriber's opt-in", record unsubscribes/complaints, or query lawful basis; curates pseudonymous consent facts through the append-only…. Consent Registry is an agent skill from aaron-he-zhu/aaron-marketing-skills. Use when the user asks to "log this subscriber's opt-in", record unsubscribes/complaints, or query lawful basis; curates pseudonymous consent facts through the append-only consent stream and applies suppression/erasure tombstones immediately.

When should I use Consent Registry?

Consent Registry fits situations like: the user asks to log this subscribers opt-in; record unsubscribes/complaints; query lawful basis; curates pseudonymous consent facts through the append-only consent stream and applies suppression/erasure tombstones immediately.

How do I install Consent Registry in Claude Code?

Run `npx skills add aaron-he-zhu/aaron-marketing-skills --skill consent-registry -a claude-code`. Or copy the skill folder (protocol/consent-registry in aaron-he-zhu/aaron-marketing-skills) into .claude/skills/consent-registry in your project. Claude Code loads it when a task matches its description.

How do I install Consent Registry in Codex?

Run `npx skills add aaron-he-zhu/aaron-marketing-skills --skill consent-registry -a codex`. Or copy the skill folder (protocol/consent-registry in aaron-he-zhu/aaron-marketing-skills) into .agents/skills/consent-registry in your project. Codex loads it when a task matches its description.

Can I use Consent Registry in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aaron-he-zhu/aaron-marketing-skills --skill consent-registry -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/consent-registry, .gemini/skills/consent-registry, .github/skills/consent-registry and .opencode/skills/consent-registry in your project.

What does Consent Registry need to run?

Going by SKILL.md and its folder, Consent Registry needs the command-line tools its instructions call (git and python3). Our summary lists: Python 3. Compatibility (from SKILL.md): Claude Code and compatible agent-skill hosts.

Does Consent Registry access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Consent Registry safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Consent Registry use?

Consent Registry is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Consent Registry use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Consent Registry?

Skills that share tags, products or a category with Consent Registry: Geo Fundamentals (wasp-lang/wasp, 19k stars), Ab Testing (coreyhaines31/marketingskills, 54k stars), Hreflang and International SEO (AgriciDaniel/claude-seo, 19k stars) and Referrals (coreyhaines31/marketingskills, 54k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Consent Registry?

aaron-he-zhu (a GitHub user) maintains it in aaron-he-zhu/aaron-marketing-skills, which has 2,891 GitHub stars. The repository holds 119 skills in this directory. The repository was last updated on October 9, 2026.

Source: aaron-he-zhu/aaron-marketing-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.