notfair-pluginBLOCK
Open-source SEO, GEO, and marketing skills for AI agents.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](LICENSE) [](https://discord.gg/gVJCRczpps)
Open-source SEO, GEO, and marketing skills for AI agents.
The NotFair Plugin gives Claude Code, Codex, Hermes, and other compatible agents practical marketing workflows they can follow—not another generic prompt collection. Use it to audit a site, investigate a traffic drop, analyze GA4 and Search Console, find wasted ad spend across Google, Meta, X, LinkedIn, Reddit, and TikTok, operate connected WordPress and GoHighLevel accounts, build campaign plans, and make reviewable changes.
Every skill is built in the open as a readable SKILL.md, with supporting references, scripts, and evals where needed. Inspect it, adapt it, or contribute a better workflow.
What your agent can do
5aefc74a2d82OBSERVED · 2026-09-21Install
Commands as the repository documents them. They are shown, not run.
pip install -r requirements-test.txt
git clone https://github.com/nowork-studio/notfair-plugin.git
git clone https://github.com/nowork-studio/notfair-plugin.git ~/.cursor/plugins/local/notfair
git clone https://github.com/nowork-studio/notfair-plugin.git
npm install notfair-nextjs-blog sanitize-html
npm install --save-dev @types/sanitize-html
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| claude-desktop | mentioned | |
| codex | mentioned | |
| cursor | mentioned | |
| gemini-cli | mentioned | |
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: gemini
argument-hint: "'review', 'challenge', or 'consult' + optional context"
description: >
Cross-model second opinion from Google Gemini — a different AI reviewing the
same changes, with deep Google ecosystem knowledge. Three modes: review
(pass/fail gate for Google Ads campaigns, SEO metadata, or code), challenge
(adversarial stress-test that tries to break your changes), and consult
(open Q&A with Gemini on Google Ads strategy, SEO best practices, or
implementation questions). Use when the user says "gemini review", "ask
gemini", "gemini challenge", "second opinion from gemini", "consult gemini",
"stress test with gemini", "what would gemini say", "cross-model review",
or "get another opinion". Voice aliases: "gem", "gemini check". Especially
useful for Google Ads changes, SEO metadata updates, campaign structure
decisions, keyword strategies, and bid/budget changes — Gemini has native
Google ecosystem knowledge that complements Claude's analysis.
triggers:
- gemini
- gemini review
- gemini challenge
- gemini consult
- ask gemini
- second opinion gemini
- stress test gemini
- gem review
- gem consult
---
# Gemini — Cross-Model Second Opinion
You are orchestrating a cross-model review by launching Google's Gemini CLI as
an independent reviewer. Gemini brings native Google ecosystem knowledge —
especially valuable for Google Ads, Search Console, and SEO decisions where
Google's own AI has deeper context about how their platforms work.
**Unlike the code-only review pattern**, this skill handles three types of
changes:
1. **Code changes** — diffs, new files, refactors
2. **Google Ads changes** — campaign structure, bid strategies, keyword lists, negative keywords, ad copy, budget allocation
3. **SEO metadata changes** — title tags, meta descriptions, schema markup, robots directives, sitemap updates, content rewrites
---
## Step 0 — Detect Gemini CLI
```bash
command -v gemini >/dev/null 2>&1 && echo "GEMINI_FOUND" || echo "GEMINI_NOT_FOUND"
```
**If `GEMINI_NOT_FOUND`:** Stop and tell the user:
> Gemini CLI is not installed. Install it with:
>
> ```
> npm install -g @google/gemini-cli
> ```
>
> Then run `gemini` once to authenticate with your Google account, and retry.
**If `GEMINI_FOUND`:** continue silently.
---
## Step 1 — Detect Mode
Parse the user's request to determine the mode. Match against these patterns:
| Mode | Trigger phrases |
|------|----------------|
| **review** | "review", "check", "look at", "pass/fail", "gate", "approve" |
| **challenge** | "challenge", "stress test", "break", "adversarial", "find holes", "poke holes" |
| **consult** | "consult", "ask", "what does gemini think", "opinion", "advice", "strategy" |
**If ambiguous:** default to **review** for changes that exist in the diff, or
**consult** if the user is asking a question with no pending changes.
---
## Step 2 — Detect Change Type
Determine what kind of changes are being reviewed. Check in this order:
### 2a — Check for Google Ads changes
Look for signs of Ads-related work in the current conversation context:
- Recent MCP tool calls to universal `mcp__NotFair__google_ads_*` tools or a supported dedicated Google Ads namespace
- Discussion of campaigns, keywords, bids, budgets, ad copy, negative keywords
- Files like `.notfair/change-log.json` or Ads-related config changes
If found, set `CHANGE_TYPE=google-ads`.
### 2b — Check for SEO metadata changes
Look for:
- Recent calls to SEO skills (seo-analysis, meta-tags-optimizer, schema-markup-generator)
- Discussion of title tags, meta descriptions, schema markup, robots.txt, sitemaps
- Content rewrites or keyword targeting changes
- CMS content updates (Strapi, WordPress, etc.)
If found, set `CHANGE_TYPE=seo`.
### 2c — Check for code changes
```bash
git diff --stat HEAD 2>/dev/null || echo "NO_GIT_DIFF"
```
If there's a diff, set `CHANGE_TYPE=code`.
### 2d — Mixed or unclear
If multiple types are present, set `CHANGE_TYPE=mixed`. If nothing is found and
mode is **consult**, set `CHANGE_TYPE=consult-only`.
---
## Step 3 — Build the Context
Assemble the context payload that Gemini will review. Tailor it to the change type.
### For `google-ads` changes:
Summarize the proposed Ads changes in a structured block:
```
GOOGLE ADS CHANGE SUMMARY
==========================
Account: [account name/ID if known]
Change type: [campaign creation | bid adjustment | keyword changes | negative keywords | ad copy | budget | targeting | etc.]
BEFORE (current state):
[Describe current campaign/keyword/bid state]
AFTER (proposed changes):
[Describe what will change]
BUSINESS CONTEXT:
[Goal of the change — CPA target, ROAS goal, traffic objective, etc.]
```
### For `seo` changes:
```
SEO CHANGE SUMMARY
==================
Site: [URL]
Change type: [title tags | meta descriptions | schema markup | content rewrite | robots.txt | sitemap | etc.]
BEFORE (current state):
[Current metadata/content]
AFTER (proposed changes):
[New metadata/content]
TARGET KEYWORDS:
[Keywords being targeted, if applicable]
SEARCH INTENT:
[Informational / navigational / commercial / transactional]
```
### For `code` changes:
```bash
BRANCH=$(git rev-parse --abbrev-ref HEAD 2>/dev/null || echo "unknown")
DIFF=$(git diff HEAD 2>/dev/null)
STAT=$(git diff --stat HEAD 2>/dev/null)
```
Combine the diff stat and full diff into the context.
### For `mixed` changes:
Combine all applicable sections above.
---
## Step 4 — Run Gemini
Build and execute the Gemini CLI command based on mode and change type.
### Review Mode
```bash
gemini -p "You are a senior reviewer with deep expertise in Google's advertising platform, Google Search, and SEO best practices. You are reviewing proposed changes for correctness, effectiveness, and potential risks.
CHANGE TYPE: ${CHANGE_TYPE}
${CONTEXT}
Evaluate these changes and produce a structured review:
1. VERDICT: PASS or FAIL (use FAIL if any blocking issue exists)
2. BLOCKING ISSTrust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
This is the safest way to grant API access — it never exposes your main password
Follow [`../docs/mcp-connection.md`](../docs/mcp-connection.md). Resolve `~~wordpress` to the live connection. Use its current instructions and capability descriptions to choose tools, and verify the
const url = `http://127.0.0.1:${port}`;const url = `http://127.0.0.1:${port}`;return hashlib.sha1(seed.encode("utf-8", "replace")).hexdigest()[:8]} from "../../bin/native-bindings.mjs";
import pkg from "../../package.json";
assert_contains "$wrapper" "../../$path/SKILL.md" "Codex skill wrapper forwards $skill to $path"
assert f"../../{canonical_rel}/SKILL.md" in wrapper_text- **`notfair-cmo/`** — open-sourced the local CMO portal as a sibling project in this repo. Node app (Next.js) that runs on `http://127.0.0.1:3000`, orchestrates specialist marketing agents (CMO, Goog
- **`/notfair:cmo`** — new slash command. Probes `http://127.0.0.1:3000`; if not running, runs `notfair-cmo doctor`, then `npx notfair-cmo@latest start` detached, then opens the browser. Supports a cu
npx notfair@latest # start in the background + open http://127.0.0.1:3327
decoded = base64.b64decode(header.split(" ")[1]).decode()decoded = base64.b64decode(header.split(" ")[1]).decode()typescript, @types/node, @types/react
@radix-ui/react-dialog, @radix-ui/react-dropdown-menu, @radix-ui/react-slot, @swc/helpers, better-sqlite3, class-variance-authority, clsx, commander
google-auth, google-auth-httplib2, requests
gemini -p "You are a senior reviewer with deep expertise in Google's advertising platform, Google Search, and SEO best practices. You are reviewing proposed changes for correctness, effectiveness, and
You are a senior SEO content strategist. Your job is to compare a target page
You are a senior e-commerce SEO specialist. Your job is to find the structural and
You are a senior international-SEO engineer. Your job is to verify that a
You are a senior local-SEO strategist. Your job is to find why a business is not
- **Standalone binary distribution** (Tauri/pkg) — V1 ships npm only; revisit if user feedback says install friction is real
- **Auto-detect quota project** — scripts now read `quota_project_id` from ADC credentials and fall back to `gcloud config get-value project` if missing, eliminating the manual `set-quota-project` ste
| Login/Access | Login page, getting started guide | Fast load, clear login form, password reset |
Gates applied: no_behavioural_pass.
5aefc74a2d82full audit observations/trust-audit/skill/nowork-studio__notfair-plugin.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-21 | 5aefc74a2d82 | BLOCK | D | 69 | first audit |
Questions
What does the notfair-plugin skill do?
Open-source SEO, GEO, and marketing skills for AI agents.
Is notfair-plugin safe to install?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What can notfair-plugin access on my machine?
The audit observed that it reaches the network, runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: none found.
Which assistants does notfair-plugin work with?
Its documentation mentions claude-code, claude-desktop, codex, cursor, gemini-cli and openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (5aefc74a2d82), read on 2026-09-21. The repository is watched, and a new audit runs when it changes — this is the first audit.