goose-skillsBLOCK
Library of Growth & GTM skills + data APIs for Claude Code, Codex, Cursor to run ads, social, content, lead gen, seo and data scraping
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Put your AI agent on the growth team.
Research customers and competitors, analyze what is working, create the next campaign, and learn from the result. Goose Skills gives Claude Code, Cursor, Codex, and other coding agents ready-to-use workflows for ads, social media, content, competitive intelligence, SEO, lead generation, and GTM.
Browse all skills at https://skills.gooseworks.ai
Works with Claude Code · Cursor · Codex
[](https://www.npmjs.com/package/goose-skills) [](LICENSE) []()
Contents
- Quick Start
- Brand Growth collection
- Commands
- Skills Catalog
- Usage Examples
- Building from Source
- Skill Metadata Contract
- Security & Trust
- License
Quick Start
AI Coding Agents (Claude Code, Cursor, Codex, etc)
Paste this into your coding agent (Claude Code, Cursor, or Codex) and it'll set everything up:
Install the Gooseworks skills: In the terminal, run `npx gooseworks install --all`. Then run `npx gooseworks login` and it'll open a browser to sign in and set up the tools, then confirm it worked. The skills can be used with /gooseworks
Claude Cowork
1c2e82b77032OBSERVED · 2026-09-29Install
Commands as the repository documents them. They are shown, not run.
git clone https://github.com/gooseworks-ai/goose-skills.git
npm install
npm install
npm i playwright-core # once (or have a cached Playwright chromium)
npm install
npm install
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| claude-desktop | mentioned | |
| codex | mentioned | |
| cursor | mentioned | |
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: answer-ads-questions
description: Answer questions about a brand's Meta ads (spend, results, which ad is winning, is it paused, why did Goose do that) only from reads made in the same turn, with the data window and sync time on every number and a plain caveat when the connection is stale or partial. Use it whenever a user asks how their ads are doing or why an ad action was taken.
---
# Answer Ads Questions
**In one line:** answer "how are my ads doing?" from a tool you called this turn, say which
days the numbers cover and when they were last synced, and say out loud when the data is
incomplete.
- **Numbers come from tools, never from memory or the docs.** The `ads/` docs explain *why*
Goose did something. They are not a source of metrics.
- **Every number carries its window and sync time.** "You spent $212 from Sep 17 to Sep 23
(data last synced Sep 24, 09:00 UTC)."
- **Partial, stale or disconnected data is said straight after the answer**, never buried or left out.
- **This skill only reads.** It never pauses, changes or writes anything.
## Where this skill's files are
Paths are relative to **this skill's own folder**, not your working directory (in GooseWorks:
`agent-config/skills/answer-ads-questions/`). The harness docs contract ships with the
`meta-ad-manager` skill, installed beside this one.
## Choose one mode
Use the first mode that is available:
1. **GooseWorks** when the GooseWorks Meta read tools are callable. Read
[references/gooseworks-adapter.md](references/gooseworks-adapter.md).
2. **Direct Meta** when there is no GooseWorks, but a Meta token with `ads_read` and the ad
account id are available. Read [references/direct-meta-adapter.md](references/direct-meta-adapter.md).
3. **Planning only** when neither is available. Read
[references/planning-only.md](references/planning-only.md).
**"The adapter"** below means the file for the mode you chose.
## Purpose
Give a user a true, dated answer about their Meta ads that they could act on. The usual way
this goes wrong is that the agent repeats a number from an earlier turn or a report, and
presents it as current. Or it misses that half the account did not sync. This skill fixes
the source (a tool read this turn) and the framing (window, sync time, connection state).
Reach for it on any question about spend, results, delivery, which ad is best or worst, whether
a push is live or paused, what Goose has noticed, or why Goose made a decision.
## Inputs
- **The user's question** (required), in their words.
- **The brand's `ads/` folder** (optional). Per the harness contract (the `meta-ad-manager` skill's `contract/RULES.md`):
`ads/README.md` first, then only the campaign in play. Read `ads/brand.md` for one field
only: `familiarity`. A brand with no `ads/` folder has never run the harness. That is fine
for metric questions. For "why" questions it means there is no recorded decision.
<!-- shared:answer-ads-questions start -->
<!-- This block is maintained in ONE place and copied byte-for-byte into both the
maintainers' source copy and the published goose-skills copy. Edit one, copy
it to the other, and run the parity script before shipping either. -->
## Workflow
### 1. Pick the read from the question
The adapter maps each read below to a real tool or API call, and says where each read's data
window and sync time come from.
| The user asks... | Read | Also read |
|---|---|---|
| "How are my ads doing?", spend, results for a period | account totals for a window | the connection state, whenever it is not clean |
| "Is Meta connected?", "why is data missing?" | the connection and sync state | the diagnostics, if the sync state does not explain it |
| "Which campaign / ad set / ad is best or worst?" | every entity at that level. **Read every page** before you rank | — |
| A trend, day by day, "since Tuesday" | a daily series for the entities in question | — |
| One specific ad | that ad's context (performance, link to Goose, freshness). If the user gave a name, find the id from the ad list first | — |
| "How are the ads Goose made doing?" | the performance of Goose's own published creatives | the connection state, for the sync time |
| A Goose push: "did it go live?", "is it paused?" | that push's state, using the push id from the campaign's `state.md` (`meta_push_ids`) | — |
| "Why did you pause / change / recommend that?" | `ads/README.md`, then that campaign's `decisions.md` | — |
| "What have you noticed?", "anything wrong?" | the campaign's `state.md` `## Open recommendations` | fresh account totals |
**Only claim a read you made.** If the host has no read for something (alerts, a watch, a push
record), never say "I checked" or "there are no alerts". Say what you did read, and that the rest
is not visible from here.
### 2. Check the connection before you say any number
For any question that ends in a Meta number, read the connection state once in the turn, in
addition to the numbers. Some reads report "ok" while the connection is only partly synced, so
the numbers' own status is not enough. The adapter says which read carries the connection
state and how each class below shows up.
| Class | What you say |
|---|---|
| **Clean**: connected, last sync finished | The numbers, with window and sync time. |
| **Partial**: some parts of the last sync failed | **Read the sync detail first.** A caveat that only says "partial" or "some data may be incomplete" fails. Name the part that failed, in plain words ("ad images didn't finish syncing"). Say which numbers that part affects. Then give them. |
| **Stale**: the last good sync is old | Give the numbers, say how old they are ("last synced 3 days ago"), and **make no recommendation**. |
| **Not connected**: never connected, needs re-authorising, failed or disconnected | No numbers. Say Meta needs reconnecting (the adapter says where). Never ask for a token in chat. |
| **Error**: the read failed, or there is no brand | Say you couldTrust audit
BLOCKgrade D · trust 61/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
POST https://api.apify.com/v2/acts/web_wanderer~amazon-reviews-extractor/runs?token=$APIFY_API_TOKEN
POST https://api.apify.com/v2/acts/trudax~reddit-scraper-lite/runs?token=$APIFY_API_TOKEN
POST https://api.apify.com/v2/acts/trudax~reddit-scraper-lite/runs?token=$APIFY_API_TOKEN
POST https://api.apify.com/v2/acts/trudax~reddit-scraper-lite/runs?token=${APIFY_API_TOKEN}POST https://api.apify.com/v2/acts/trudax~reddit-scraper-lite/runs?token=$APIFY_API_TOKEN
Read your credentials from ~/.gooseworks/credentials.json:
Read your credentials from ~/.gooseworks/credentials.json:
Read your credentials from ~/.gooseworks/credentials.json:
**Prerequisites:** [What they need before starting — e.g., "Admin access, API key"]
Read your credentials from ~/.gooseworks/credentials.json:
# Add to ~/.bashrc or ~/.zshrc
## Important: Always Include Post URLs
key-tap.wav
response-done.wav
send-tap.wav
stream-tick.wav
("HelpScout", "chat", r"helpscout\.net|beacon-v2\.helpscout\.net"),exam_html += (f'<div class="card"><div class="card-h">🧑⚖️ Exam Q{i+1}: {esc(title(tid))}'const emojiRe = /^(\p{Extended_Pictographic}|\p{Emoji_Presentation}|️||\s)+$/u;const re = /^(\p{Extended_Pictographic}|\p{Emoji_Presentation}|️||\s)+$/u;const emojiRe = /^(\p{Extended_Pictographic}|\p{Emoji_Presentation}|️||\s)+$/u;- **Multi-format** — If the user says "make this as both a carousel and an infographic," run the full workflow twice using the same content and style but different format slugs. Save outputs in separa
url_hash = hashlib.md5(normalize_linkedin_url(linkedin_url).encode()).hexdigest()[:12]
cache_hash = hashlib.md5(key.lower().encode()).hexdigest()[:12]
return base64.b64decode(content).decode("utf-8", errors="replace")Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
1c2e82b77032full audit observations/trust-audit/skill/gooseworks-ai__goose-skills.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 1c2e82b77032 | BLOCK | D | 61 | first audit |
Questions
What does the goose-skills skill do?
Library of Growth & GTM skills + data APIs for Claude Code, Codex, Cursor to run ads, social, content, lead gen, seo and data scraping
Is goose-skills safe to install?
No — not without reading the findings first. The audit graded it D (61/100) and found 12 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What can goose-skills access on my machine?
The audit observed that it reaches the network, runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: none found.
Which assistants does goose-skills work with?
Its documentation mentions claude-code, claude-desktop, codex, cursor and openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (1c2e82b77032), read on 2026-09-29. The repository is watched, and a new audit runs when it changes — this is the first audit.