* feat: add prospecting skill + truelist integration New skill: skills/prospecting/ - SKILL.md (251 lines, well under 500 limit): branch picker for SaaS / B2B / Local SMB, shared 5-phase framework (ICP -> discovery -> qualify -> score -> output), compliance guardrails, tool selection quick-picks, output formats - references/saas-prospecting.md: tech stack signals, funding/hiring triggers, SaaS-specific sources and qualification - references/b2b-prospecting.md: industry/firmographic signals, trigger events, decision-maker mapping, B2B-specific sources - references/local-prospecting.md: 4-tier website status classification, browser-assisted research workflow (generalized from the local-client- prospector pattern), proximity scoring - references/data-sources.md: deep dives on Apollo, Clay, ZoomInfo, Clearbit, Hunter, Snov, Truelist, LinkedIn Sales Nav, BuiltWith, Crunchbase, RB2B, with sequencing recommendations across the three branches - references/compliance.md: CAN-SPAM, GDPR, CASL, platform ToS (LinkedIn, Google Maps, Apollo/ZI/Clearbit), anti-patterns, audit checklist - evals/evals.json: 6 evals (2 SaaS, 2 B2B, 1 Local SMB, 1 deliverability) New integration: - tools/integrations/truelist.md: email deliverability validation (Deliverable / Risky / Undeliverable / Unknown classification) Registry + marketplace wiring: - tools/REGISTRY.md: truelist row + new Email Verification category section - .claude-plugin/marketplace.json: bumped to 2.1.0, prospecting added to plugin description - VERSIONS.md: prospecting 1.0.0 + 2.1.0 changelog entry - README.md: skill table re-synced, prospecting added to ASCII flow under Sales & GTM column All 41 skills pass validation. sync-skills.js is idempotent. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * feat(prospecting): add GitHub stargazers/forks/watchers as discovery channel Net-new in this commit: - tools/clis/github-prospects.js: zero-dep Node CLI with commands stargazers / forks / watchers / user / rate-limit. Pagination via Link header, optional --enrich for full profile data, --with-email / --with-company / --with-blog filters, --format csv|json output, --dry-run preview. Uses GITHUB_TOKEN for 5000/hr rate limit (vs 60/hr unauthenticated). - tools/integrations/github.md: integration guide covering auth, rate limits, endpoints, workflows for SaaS prospecting, compliance notes (public API, not scraping), CLI reference. Skill updates: - skills/prospecting/SKILL.md: added GitHub to the tool selection quick picks and to the tool integrations table. - skills/prospecting/references/saas-prospecting.md: added GitHub to Tier 3 buying signals plus a dedicated "GitHub prospecting pattern (when audience is developers)" subsection with end-to-end workflow. - skills/prospecting/references/data-sources.md: added GitHub deep-dive section between RB2B and Free fallbacks. Registry: - tools/REGISTRY.md: github row in Tool Index, new Developer Intent / GitHub category section. All 41 skills still pass validation. sync-skills.js still no-op. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * refactor(prospecting): apply review suggestions CLI hardening + optimization: - github-prospects.js: encodeURIComponent on username path interpolation (defense in depth; GitHub usernames are restricted enough that this is safe in practice, but good hygiene). - github-prospects.js: refactored enrichUsers to filter inline and support --target N early termination. Previously, --with-email on a 1000-star repo would enrich all 1000 users before filtering down to the ~50 that match. Now you can pass --target 25 to stop as soon as 25 matches are found, saving API quota on restrictive filters. - github.md: documented the new --target flag. Reverse cross-references (so prospecting is discoverable from sibling skills): - cold-email: added prospecting as the natural upstream skill - customer-research: added "Translating customer research into an ICP for outbound" hand-off to prospecting - competitor-profiling: distinguished from prospecting ("this skill does deep research on specific accounts; prospecting builds the initial list") All 41 skills still pass validation. sync-skills.js still no-op. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(truelist): align integration doc with actual OpenAPI spec Source of truth: Truelist-Labs/truelist-openapi (OpenAPI 3.1). The earlier integration doc had inferred (and wrong) endpoint paths, request shapes, and status enum values. Corrected against the published spec: Base URL: https://api.truelist.io Endpoints (real): - POST /api/v1/verify_inline?email=... (sync single, email is query param) - POST /api/v1/verify (async bulk, body: {emails: [...]}) - GET /me (account info) Real email_state enum: - ok, email_invalid, risky, unknown, accept_all (not the inferred "Deliverable / Risky / Undeliverable / Unknown") Real email_sub_state enum: - email_ok, is_disposable, is_role, unknown_error, failed_smtp_check Also corrected: - Truelist has an official MCP server (Truelist-Labs/truelist-mcp) — was marked as MCP unavailable - Truelist has 7 official SDKs (Node, Python, Ruby, PHP, Go, Java, .NET) + framework integrations (Django, Laravel, Next.js, Rails, React, Svelte, Vue, WordPress) — was marked as SDK unavailable - Native integrations with Mailchimp, Klaviyo, HubSpot, Zapier, Make, n8n, Clay, Salesforce, ActiveCampaign, Brevo, ConvertKit, Drip, BigCommerce, Go High Level — was unlisted - Rate limits: 10 req/s per endpoint (was unspecified) Files updated: - tools/integrations/truelist.md: full rewrite against spec - tools/REGISTRY.md: MCP and SDK columns now show ✓ for truelist; classifier note in the Email Verification section reflects real enum values - skills/prospecting/evals/evals.json: eval #6 expected_output and assertions use real email_state values and mention the MCP server - skills/prospecting/references/data-sources.md: Truelist deep-dive uses real endpoint paths, real enum values, and lists the MCP/SDK ecosystem All 41 skills still pass validation. sync-skills.js still no-op. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * feat(prospecting): add Firecrawl + Browserbase for single-target site research Both tools are programmatic scrapers, but their use in prospecting is strictly bounded: extract content from individual public business sites (the prospect's own website URL), never from the platforms hosting them (Google Maps, LinkedIn, Yelp, Apollo, etc.). This matches the line drawn by the original local-client-prospector reference skill and our own compliance section. New integration docs: - tools/integrations/firecrawl.md: REST + MCP + SDKs (Node/Python/Go/Rust); scrape / map / crawl / extract / search endpoints; explicit "when NOT to use" section listing the prohibited platforms. - tools/integrations/browserbase.md: real Chromium via Playwright/Puppeteer or Stagehand (AI-friendly natural-language extraction); session recordings; useful when rendering or interaction is required. Prospecting skill updates: - SKILL.md: added Firecrawl + Browserbase to tool selection quick picks and tool integrations table. - references/data-sources.md: new "Firecrawl / Browserbase (single-target site research)" section between RB2B and Free fallbacks. Includes the compliance line inline so the framing isn't lost. - references/local-prospecting.md: optional "programmatic verification" paragraph in the browser research workflow — once you have a candidate's URL from manual Maps discovery, you can hit it programmatically. - references/compliance.md: anti-pattern #1 now explicitly clarifies that Firecrawl/Browserbase are fine for the prospect's own website but not for the platforms hosting prospects. Registry: - tools/REGISTRY.md: firecrawl + browserbase rows in Tool Index, new "Site Scraping (single-target only)" category section with the compliance framing in the agent recommendation. All 41 skills still pass validation. sync-skills.js still no-op. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
7.4 KiB
Truelist
Email verification and deliverability validation. Validates single emails synchronously or bulk lists asynchronously. Returns an email_state + email_sub_state plus rich metadata (domain, MX record, suggested correction, disposable/role classification).
Spec source: Truelist-Labs/truelist-openapi (OpenAPI 3.1).
Capabilities
| Integration | Available | Notes |
|---|---|---|
| API | ✓ | REST API, OpenAPI 3.1 spec |
| MCP | ✓ | Official truelist-mcp server (Claude, Cursor, VS Code) |
| CLI | ✓ | Official Go truelist-cli |
| SDK | ✓ | Official: Node/TypeScript, Python, Ruby, PHP, Go, Java, C#/.NET. Framework integrations: Django, Laravel, Next.js, Rails, React, Svelte, Vue, WordPress |
Authentication
- Type: Bearer token (API key)
- Header:
Authorization: Bearer YOUR_API_KEY - Get key: https://truelist.io/settings/api-keys
- Base URL:
https://api.truelist.io
Common Agent Operations
Verify a single email (synchronous)
POST https://api.truelist.io/api/v1/verify_inline?email=user@example.com
Authorization: Bearer YOUR_API_KEY
No request body — the email is a query parameter. Returns a single-element emails array with verification fields:
{
"emails": [
{
"address": "user@example.com",
"domain": "example.com",
"canonical": "user@example.com",
"mx_record": null,
"first_name": null,
"last_name": null,
"email_state": "ok",
"email_sub_state": "email_ok",
"verified_at": "2026-02-21T10:39:12.570Z",
"did_you_mean": null
}
]
}
Bulk verification (asynchronous)
POST https://api.truelist.io/api/v1/verify
Authorization: Bearer YOUR_API_KEY
Content-Type: application/json
{
"emails": [
"user1@example.com",
"user2@example.com"
]
}
Processes the list in the background. The response acknowledges submission; results are available via the dashboard, the Truelist UI's CSV download, or via integrations (Mailchimp, Klaviyo, HubSpot, Zapier, Make, n8n, etc.).
For large lists, the dashboard's CSV upload + download flow is typically the lowest-friction path.
Get account information
GET https://api.truelist.io/me
Authorization: Bearer YOUR_API_KEY
Returns email, name, UUID, time zone, admin role, API keys, and account plan info.
Response Fields (per email)
| Field | Type | Description |
|---|---|---|
address |
string | The email address validated |
domain |
string | The domain part of the address |
canonical |
string | Canonical form of the address |
mx_record |
string | null | MX record for the domain |
first_name |
string | null | First name if detected |
last_name |
string | null | Last name if detected |
email_state |
enum | Overall validation verdict (see below) |
email_sub_state |
enum | More specific reason (see below) |
verified_at |
datetime (ISO 8601) | When verification ran |
did_you_mean |
string | null | Suggested correction for typos |
email_state values
| State | Meaning | What to do |
|---|---|---|
ok |
The email address is deliverable. | Include in outreach |
email_invalid |
The email address is not deliverable. | Exclude — would bounce |
risky |
May be deliverable but carries risk (role address, disposable, etc.) | Include cautiously, lower priority |
unknown |
Deliverability could not be determined (timeout/connection). | Skip or re-verify with Thorough strategy |
accept_all |
The mail server accepts all addresses (catch-all domain) | Include cautiously — can't confirm specific mailbox |
email_sub_state values
| Sub-state | Meaning |
|---|---|
email_ok |
Passed all checks |
is_disposable |
Disposable / temporary provider (e.g., 10minutemail) |
is_role |
Role-based address (info@, sales@, admin@) |
unknown_error |
Sub-state could not be determined |
failed_smtp_check |
SMTP check failed |
Pair the two: email_state: ok + email_sub_state: is_role means "deliverable but a role inbox," whereas email_state: email_invalid + email_sub_state: failed_smtp_check means "doesn't exist."
Rate Limits
| Endpoint | Limit |
|---|---|
/api/v1/verify_inline |
10 requests/second |
/api/v1/verify |
10 requests/second |
/me |
10 requests/second |
A 429 is returned on rate-limit exceed. Note: the per-email validation rate is separate and depends on your plan.
Error Responses
| Code | Meaning |
|---|---|
| 401 | Unauthorized — API key missing, invalid, or expired |
| 429 | Rate limit exceeded |
| 500 | Server error |
All error bodies follow {"error": "<human-readable message>"}.
When to Use
- Before adding contacts to any cold outreach list — non-negotiable safety step. Apollo/ZoomInfo/Hunter data accuracy is typically 60–80%; Truelist catches the rest.
- Real-time form validation — block disposable / typo'd emails at signup. Use the inline endpoint (or the form validation widget).
- Periodic list hygiene — re-verify your active list quarterly to remove bounces before they hurt sender reputation.
- Pre-import validation on email platform imports (Mailchimp, Klaviyo, HubSpot, etc.) — direct integrations exist for most.
- AI agent workflows via the official MCP server for Claude, Cursor, and VS Code.
Why This Step is Non-Negotiable
Cold email reputation is built over months and destroyed in days. ISPs (Gmail, Outlook, etc.) track sender reputation through:
- Bounce rate — bounces over 2% trigger throttling
- Spam complaints — spam traps in unvalidated lists generate complaints
- Engagement — sending to dead mailboxes hurts engagement metrics
A single unvalidated send to a bought or scraped list can damage a domain's sending reputation for months.
Workflow Integration
Typical prospecting flow:
- Build initial prospect list (Apollo, Clay, ZoomInfo, Hunter, GitHub stargazers, etc.)
- For agent-driven workflows: use the Truelist MCP server to validate inline as the agent builds the list
- For programmatic workflows: POST emails to
/api/v1/verifyfor async bulk OR/api/v1/verify_inlinefor sync single - For one-offs: CSV upload via dashboard, download annotated CSV
- Filter: keep
email_state: ok, includerisky/accept_allcautiously with a strategy, excludeemail_invalid, re-verifyunknown - Hand cleaned list to outreach platform (Instantly, Lemlist, Outreach, etc.) — see outreach.md, instantly.md, lemlist.md
Native Integrations (no API code required)
For non-developer workflows, Truelist has direct integrations:
- Email platforms: Mailchimp, Klaviyo, HubSpot, ActiveCampaign, Brevo, Constant Contact, ConvertKit, Drip
- Automation: Zapier, Make.com, n8n
- CRM / sales: Salesforce, Go High Level, Clay.com
- Ecom: BigCommerce
- AI / agents: MCP server (Claude, Cursor, VS Code)
See https://truelist.io/integrations for the current list.
Relevant Skills
- prospecting (primary use case — validate before adding to outreach lists)
- cold-email (downstream outreach against the validated list)
- emails (transactional senders + subscriber list hygiene)
- popups (real-time form validation on opt-in capture)