SKILL.md
OXYGEN Email Infrastructure
Own sending beneath Messages and Sequences. Discover with oxygen capabilities search "email infrastructure <goal>" --json. Import uses mailboxes compatibility|import|connect-oauth|oauth-health; removal uses the preview-first mailboxes delete contract.
Readiness chain
- Inspect domains and mailbox addresses.
- Preview the live quote; treat it as pricing truth. Orders use a sender profile
(--sender <id>); its name/photo are permanent, so read back senders[] and stop at avatardurable: false ([InboxKit](provider-runbooks/inboxkit.md)). Get approval before purchases, subscriptions, writes, or recurring charges. Managed auto-warmup exists only at warmupactivation.automaticafterprovisioning=true.
- Verify nameservers, SPF, DKIM, DMARC, MX, and tracking.
- Check
mailboxes oauth-health|compatibility. For anautomaticrepair, wait
for nextattemptat; otherwise follow the stated remedy. Google/ordinary Microsoft use OAuth; dedicated Microsoft tenants use an admin grant + Graph check.
- Continue every eligible address to OXYGEN Warm-up; check
mailboxes warmup status.
Managed scope needs no second approval; otherwise preview exact scope, ramp, price, and cap. Managed Google passes its source credential in memory; Microsoft/Azure uses native export. Consent does not transfer; keep monitoring separate. On a paid seat, warmupRepair.mode=automatic means bounded 0-credit repair. Only manual/exhausted needs credential correction plus warmup reconnect; never disable, which cancels and re-bills 3,000/inbox.
- Inspect health and auto-pause, set caps/[egress](provider-runbooks/egress.md), then attach senders.
Warmup authority never authorizes sending.
Disconnect selected mailboxes
Preview exact addresses before removal:
oxygen mailboxes delete --mailboxes [email protected] --json
Before approval, explain: sending stops at once; OXYGEN OAuth credentials are cleared but the Google/Microsoft accounts themselves are never deleted; Messages and delivery history remain; 1,000 recurring credits per mailbox stop at the next renewal, with no refund for the current period. Name every active/paused Sequence at risk — each keeps its status but loses those senders and is not auto-paused. Execute only with the fresh planhash and exact confirmationphrase.
Do not bypass a blocker: managed subscriptions, warmup, and monitoring are separate recurring lines and must be torn down through their own lifecycle first. Re-import is the restore path and needs fresh OAuth.
Focused references
Managed: [InboxKit](provider-runbooks/inboxkit.md). Import/BYO: [generic import](provider-runbooks/mailbox-import.md), [Zapmail](provider-runbooks/zapmail.md). Delivery: [OXYGEN Warm-up](provider-runbooks/oxygen-warmup.md), [EmailGuard](provider-runbooks/emailguard.md). Network: [Cloudflare](provider-runbooks/cloudflare.md), [egress](provider-runbooks/egress.md).
Fail closed
Surface missing authority, consent, balance, or readiness. Never paste secrets, edit env files, fake readiness, or quote a prose price. Show live previews; return deep-links for writes.