Atlas / Skills / nowork-studio / Gemini

GeminiSAFE

skills/nowork-studio/gemini

Open-source SEO, GEO, and marketing skills for AI agents.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
—
Hosts
1 documented
License
MIT
Stars
3,908
01

Overview

Open-source SEO, GEO, and marketing skills for AI agents.

Read from source at commit f08bca773eb5OBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
gemini-climentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: gemini
argument-hint: "'review', 'challenge', or 'consult' + optional context"
description: >
  Cross-model second opinion from Google Gemini — a different AI reviewing the
  same changes, with deep Google ecosystem knowledge. Three modes: review
  (pass/fail gate for Google Ads campaigns, SEO metadata, or code), challenge
  (adversarial stress-test that tries to break your changes), and consult
  (open Q&A with Gemini on Google Ads strategy, SEO best practices, or
  implementation questions). Use when the user says "gemini review", "ask
  gemini", "gemini challenge", "second opinion from gemini", "consult gemini",
  "stress test with gemini", "what would gemini say", "cross-model review",
  or "get another opinion". Voice aliases: "gem", "gemini check". Especially
  useful for Google Ads changes, SEO metadata updates, campaign structure
  decisions, keyword strategies, and bid/budget changes — Gemini has native
  Google ecosystem knowledge that complements Claude's analysis.
triggers:
  - gemini
  - gemini review
  - gemini challenge
  - gemini consult
  - ask gemini
  - second opinion gemini
  - stress test gemini
  - gem review
  - gem consult
---

# Gemini — Cross-Model Second Opinion

You are orchestrating a cross-model review by launching Google's Gemini CLI as
an independent reviewer. Gemini brings native Google ecosystem knowledge —
especially valuable for Google Ads, Search Console, and SEO decisions where
Google's own AI has deeper context about how their platforms work.

**Unlike the code-only review pattern**, this skill handles three types of
changes:

1. **Code changes** — diffs, new files, refactors
2. **Google Ads changes** — campaign structure, bid strategies, keyword lists, negative keywords, ad copy, budget allocation
3. **SEO metadata changes** — title tags, meta descriptions, schema markup, robots directives, sitemap updates, content rewrites

---

## Step 0 — Detect Gemini CLI

```bash
command -v gemini >/dev/null 2>&1 && echo "GEMINI_FOUND" || echo "GEMINI_NOT_FOUND"
```

**If `GEMINI_NOT_FOUND`:** Stop and tell the user:

> Gemini CLI is not installed. Install it with:
>
> ```
> npm install -g @google/gemini-cli
> ```
>
> Then run `gemini` once to authenticate with your Google account, and retry.

**If `GEMINI_FOUND`:** continue silently.

---

## Step 1 — Detect Mode

Parse the user's request to determine the mode. Match against these patterns:

| Mode | Trigger phrases |
|------|----------------|
| **review** | "review", "check", "look at", "pass/fail", "gate", "approve" |
| **challenge** | "challenge", "stress test", "break", "adversarial", "find holes", "poke holes" |
| **consult** | "consult", "ask", "what does gemini think", "opinion", "advice", "strategy" |

**If ambiguous:** default to **review** for changes that exist in the diff, or
**consult** if the user is asking a question with no pending changes.

---

## Step 2 — Detect Change Type

Determine what kind of changes are being reviewed. Check in this order:

### 2a — Check for Google Ads changes

Look for signs of Ads-related work in the current conversation context:
- Recent MCP tool calls to universal `mcp__NotFair__google_ads_*` tools or a supported dedicated Google Ads namespace
- Discussion of campaigns, keywords, bids, budgets, ad copy, negative keywords
- Files like `.notfair/change-log.json` or Ads-related config changes

If found, set `CHANGE_TYPE=google-ads`.

### 2b — Check for SEO metadata changes

Look for:
- Recent calls to SEO skills (seo-analysis, meta-tags-optimizer, schema-markup-generator)
- Discussion of title tags, meta descriptions, schema markup, robots.txt, sitemaps
- Content rewrites or keyword targeting changes
- CMS content updates (Strapi, WordPress, etc.)

If found, set `CHANGE_TYPE=seo`.

### 2c — Check for code changes

```bash
git diff --stat HEAD 2>/dev/null || echo "NO_GIT_DIFF"
```

If there's a diff, set `CHANGE_TYPE=code`.

### 2d — Mixed or unclear

If multiple types are present, set `CHANGE_TYPE=mixed`. If nothing is found and
mode is **consult**, set `CHANGE_TYPE=consult-only`.

---

## Step 3 — Build the Context

Assemble the context payload that Gemini will review. Tailor it to the change type.

### For `google-ads` changes:

Summarize the proposed Ads changes in a structured block:

```
GOOGLE ADS CHANGE SUMMARY
==========================
Account: [account name/ID if known]
Change type: [campaign creation | bid adjustment | keyword changes | negative keywords | ad copy | budget | targeting | etc.]

BEFORE (current state):
[Describe current campaign/keyword/bid state]

AFTER (proposed changes):
[Describe what will change]

BUSINESS CONTEXT:
[Goal of the change — CPA target, ROAS goal, traffic objective, etc.]
```

### For `seo` changes:

```
SEO CHANGE SUMMARY
==================
Site: [URL]
Change type: [title tags | meta descriptions | schema markup | content rewrite | robots.txt | sitemap | etc.]

BEFORE (current state):
[Current metadata/content]

AFTER (proposed changes):
[New metadata/content]

TARGET KEYWORDS:
[Keywords being targeted, if applicable]

SEARCH INTENT:
[Informational / navigational / commercial / transactional]
```

### For `code` changes:

```bash
BRANCH=$(git rev-parse --abbrev-ref HEAD 2>/dev/null || echo "unknown")
DIFF=$(git diff HEAD 2>/dev/null)
STAT=$(git diff --stat HEAD 2>/dev/null)
```

Combine the diff stat and full diff into the context.

### For `mixed` changes:

Combine all applicable sections above.

---

## Step 4 — Run Gemini

Build and execute the Gemini CLI command based on mode and change type.

### Review Mode

```bash
gemini -p "You are a senior reviewer with deep expertise in Google's advertising platform, Google Search, and SEO best practices. You are reviewing proposed changes for correctness, effectiveness, and potential risks.

CHANGE TYPE: ${CHANGE_TYPE}

${CONTEXT}

Evaluate these changes and produce a structured review:

1. VERDICT: PASS or FAIL (use FAIL if any blocking issue exists)

2. BLOCKING ISS
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
SKILL.md:186
gemini -p "You are a senior reviewer with deep expertise in Google's advertising platform, Google Search, and SEO best practices. You are reviewing proposed changes for correctness, effectiveness, and

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f08bca773eb5full audit observations/trust-audit/skill/nowork-studio__gemini.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-08f08bca773eb5SAFEB89first audit
06

Questions

What does the Gemini skill do?

Open-source SEO, GEO, and marketing skills for AI agents.

Is Gemini safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Gemini access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Gemini work with?

Its documentation mentions gemini-cli. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (f08bca773eb5), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement