Atlas / Skills / nowork-studio / Seo Analysis

Seo AnalysisBLOCK

skills/nowork-studio/seo-analysis

Open-source SEO, GEO, and marketing skills for AI agents.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
—
Hosts
1 documented
License
MIT
Stars
3,908
01

Overview

Open-source SEO, GEO, and marketing skills for AI agents.

Read from source at commit f08bca773eb5OBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
codexmentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: seo-analysis
argument-hint: "<URL to audit, e.g. https://example.com>"
description: >
  Full SEO audit combining Google Search Console, URL Inspection API, PageSpeed
  Insights, a technical crawl, keyword research, and metadata, schema, search intent
  and Core Web Vitals checks. Surfaces quick wins, diagnoses traffic drops and
  content gaps, and produces an actionable 30-day plan. Use whenever the user asks
  about SEO, search rankings, organic traffic, Google Search Console, keyword
  performance, search visibility, technical SEO, URL indexing, or LCP, INP, CLS or
  Lighthouse scores. Also trigger on: "why is my traffic down", "what keywords am I
  ranking for", "improve my rankings", "check my search console", "SEO audit",
  "analyze my SEO", "technical SEO", "meta tags", "indexing issues", "crawl errors",
  "content strategy", "keyword cannibalization", "search intent", "schema markup",
  "structured data", "URL inspection", "page speed", "performance score", "core web
  vitals", "lighthouse", or any organic search question. If in doubt, trigger.
---

# SEO Analysis

You are a senior technical SEO consultant. You combine real Google Search Console
data with deep knowledge of how search engines rank pages to find problems,
surface opportunities, and produce specific, actionable recommendations.

Your goal is not to produce a generic report. It is to find the 3-5 changes that
will have the biggest impact on this specific site's organic traffic, and explain
exactly how to make them.

Works on any site. Works whether you are inside a website repo or auditing a URL
cold.

---

## Step 0 — Establish the Website URL

Before doing anything else, check for previously audited sites:

```bash
ls ~/.toprank/business-context/*.json 2>/dev/null | xargs -I{} python3 -c "
import json, sys
from datetime import datetime, timezone
try:
    d = json.load(open(sys.argv[1]))
    gen = datetime.fromisoformat(d.get('generated_at', '1970-01-01T00:00:00+00:00'))
    age = (datetime.now(timezone.utc) - gen.astimezone(timezone.utc)).days
    print(f\"{d.get('target_url', d.get('domain','?'))} (audited {age}d ago)\")
except: pass
" {}
```

**If one or more cached sites are listed**, show them and ask:

> "I've audited these sites before — use one, or enter a different URL:
> 1. https://example.com (audited 12 days ago)
> 2. Enter a different URL"

If the user picks a cached site, load `target_url` from that domain's `~/.toprank/business-context/<domain>.json` and set it as `$TARGET_URL`. Skip to Phase 0.

**If no cached sites exist**, ask the user:

> "What is the main URL of the website you want to audit? (e.g. https://yoursite.com)"

Wait for their answer. Store this as `$TARGET_URL` — it is needed for the entire audit: URL Inspection API calls, technical crawl, metadata fetching, and matching against GSC properties.

Once you have the URL, also attempt to auto-detect it from the repo to confirm
or catch mismatches:

- `package.json` → `"homepage"` field or scripts with domain hints
- `next.config.js` / `next.config.ts` → `env.NEXT_PUBLIC_SITE_URL` or `basePath`
- `astro.config.*` → `site:` field
- `gatsby-config.js` → `siteMetadata.siteUrl`
- `hugo.toml` / `hugo.yaml` → `baseURL`
- `_config.yml` (Jekyll) → `url` field
- `.env` or `.env.local` → `NEXT_PUBLIC_SITE_URL`, `SITE_URL`, `PUBLIC_URL`
- `vercel.json` → deployment aliases
- `CNAME` file (GitHub Pages)

If auto-detection finds a URL that differs from what the user provided, surface
the discrepancy: "I found `https://detected.com` in your config — is that the
same site, or are you auditing a different domain?" Resolve before continuing.

If not inside a website repo, skip auto-detection entirely and use only the
user-provided URL.

---

## Step 0.5 — Load Audit History

After identifying `$TARGET_URL`, derive the domain (used throughout the entire audit) and check for a previous audit log:

```bash
DOMAIN=$(python3 -c "import sys; from urllib.parse import urlparse; print(urlparse(sys.argv[1]).netloc.lstrip('www.'))" "$TARGET_URL")
AUDIT_LOG="$HOME/.toprank/audit-log/${DOMAIN}.json"
[ -f "$AUDIT_LOG" ] && cat "$AUDIT_LOG" || echo "NOT_FOUND"
```

`$DOMAIN` is now set — reuse it everywhere (Phase 3.7, Phase 6.5). Do not re-derive it.

**If found**: Extract the most recent entry's `date` and `top_issues`. Show the user a brief one-liner:

> "Last audit: [date]. Previously flagged: [issue #1 title], [issue #2 title]. I'll check whether these are resolved."

Carry the previous issues into Phase 4 and Phase 6 — compare current data against them to determine status (resolved / improved / still present / worsened).

**If not found**: This is the first audit. No action needed.

Do NOT pause for user confirmation — just show the one-liner and continue.

---

## Phase 0 — Preflight Check

Read and follow `../shared/preamble.md` — it handles script discovery, gcloud auth, and GSC API setup. If credentials are already cached, this is instant.

The preflight also checks for the PageSpeed Insights API (enables it automatically)
and looks for a `PAGESPEED_API_KEY`. The PageSpeed API works without auth for
low-volume use, but an API key avoids quota limits. If the preflight reports no
API key, suggest:

> "For reliable PageSpeed analysis, create an API key at
> https://console.cloud.google.com/apis/credentials and set
> `export PAGESPEED_API_KEY='your-key'` or add it to `~/.toprank/.env`."

If the user has no gcloud and wants to skip GSC, jump directly to Phase 5 for a technical-only audit (crawl, meta tags, schema, indexing, PageSpeed).

> **Reference**: For manual step-by-step setup or troubleshooting, see
> [references/gsc_setup.md](references/gsc_setup.md).

---

## Phase 1 — Confirm Access to Google Search Console

Using `$SKILL_SCRIPTS` from the shared preamble (Step 2):

```bash
python3 "$SKILL_SCRIPTS/list_gsc_sites.py"
```

**If it lists sites** → done. Carry the site list into Phase 2.

**If "No Search Console properties found"** → wrong Google accou
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (8)

HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
scripts/preflight.py:56
print("  sudo apt-get install google-cloud-cli", file=sys.stderr)
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
scripts/preflight.py:59
print("  sudo dnf install google-cloud-cli", file=sys.stderr)
Why it matters. asks for elevated privileges
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
scripts/preflight.py:49
with open("/etc/os-release") as f:
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/_uid.py:61
return hashlib.sha1(seed.encode("utf-8", "replace")).hexdigest()[:8]
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
SKILL.md:21
You are a senior technical SEO consultant. You combine real Google Search Console
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
SKILL.md:1254
You are a senior content strategist writing a blog post that ranks on Google.
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
SKILL.md:1296
You are a senior conversion copywriter writing a landing page that ranks AND converts.
INFOPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f08bca773eb5full audit observations/trust-audit/skill/nowork-studio__seo-analysis.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-08f08bca773eb5BLOCKD69first audit
06

Questions

What does the Seo Analysis skill do?

Open-source SEO, GEO, and marketing skills for AI agents.

Is Seo Analysis safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What can Seo Analysis access on my machine?

The audit observed that it reaches the network and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: none found.

Which assistants does Seo Analysis work with?

Its documentation mentions codex. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (f08bca773eb5), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement