{"id":"4afcbdfb-3d03-4af1-ae9c-2bc495d49beb","entityType":"agent","slug":"clawhub-samber-site-launch-checklist","name":"site-launch-checklist","canonicalUrl":"https://www.xpersona.co/agent/clawhub-samber-site-launch-checklist","canonicalPath":"/agent/clawhub-samber-site-launch-checklist","generatedAt":"2026-10-11T17:43:27.695Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:39:22.927Z","emptyReason":null},"description":"Pre-launch checklist for shipping a new website. Orchestrates analytics setup (GA4, PostHog, Google Search Console, Ahrefs), legal compliance, security headers and audit, SEO and GEO with keyword research validated against Google Trends (robots.txt, sitemaps, llms.txt, AI policy, schema markup, hreflang), copywriting consistency via a TONE.md and a humanizer pass in the matching language, OpenGraph and social previews, full favicon set with manifest, quality gates (Lighthouse, Core Web Vitals, WCAG accessibility, mobile testing), and setup of a weekly SEO agent. Use this skill whenever the user mentions launching a site/app, deploying a domain to production, pre-launch audit, shipping a marketing/docs/SaaS site or lead magnet, or says \"checklist for the site\", \"ready to ship\", \"before I go live\", \"audit before launch\", \"ready for prod\", or asks for a site review.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s173arkhs3131fq5jf769qq75583hdgt:site-launch-checklist","sourceUrl":"https://clawhub.ai/samber/site-launch-checklist","homepage":"https://clawhub.ai/samber/skills/site-launch-checklist","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/samber/site-launch-checklist","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/samber/skills/site-launch-checklist","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":60,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"site-launch-checklist technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:39:22.927Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:39:22.927Z","emptyReason":null},"stars":null,"forks":null,"downloads":1037,"packageName":null,"latestVersion":"1.2.0","tractionLabel":"1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:39:22.791Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T15:39:22.927Z","lastCrawledAt":"2026-10-11T15:39:22.791Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T15:39:22.791Z","lastVerifiedAt":null,"highlights":[{"version":"1.2.0","createdAt":"2026-08-21T12:13:49.125Z","changelog":"site-launch-checklist 1.2.0 - Added new weekly SEO agent assets and references for improved SEO workflow. - Expanded companion SEO/marketing skill references, including new decision docs. - Updated compatibility notice to include Codex and clarify harnesses. - Improved user question handling: always uses the environment’s question tool when available. - Interaction and install flow clarified; wording streamlined. - Removed obsolete skill-card.md.","fileCount":14,"zipByteSize":40479},{"version":"1.1.0","createdAt":"2026-06-10T15:19:37.099Z","changelog":"site-launch-checklist 1.1.0 - Removed the obsolete skill-card.md file. - Updated SKILL.md metadata to version 1.1.0. - No functional or logic changes; documentation and structure cleanup only.","fileCount":7,"zipByteSize":31510},{"version":"1.0.3","createdAt":"2026-05-22T01:21:11.678Z","changelog":"site-launch-checklist v1.0.3 - Expanded the SKILL.md to include detailed, step-by-step interaction and confirmation logic for all phases of a pre-launch site checklist. - Added strict, checkpoint-based user input requirements at every decision point, with specific prompts for site type, migration, multilingual setup, analytics, legal policies, and browser tools. - Outlined a clear workflow for sub-skill and companion skill pack selection, ensuring only the needed subset is installed per site type and phase. - Clarified procedures for copywriting polishing, including defining a TONE.md and enforcing a mandatory humanizer pass in the site's main language. - Enhanced guidance on security, SEO/GEO, and quality audits via specialized skills and agents, all orchestrated interactively.","fileCount":7,"zipByteSize":31030}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173arkhs3131fq5jf769qq75583hdgt:site-launch-checklist","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s173arkhs3131fq5jf769qq75583hdgt:site-launch-checklist` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/samber/site-launch-checklist before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-samber-site-launch-checklist/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-samber-site-launch-checklist/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-samber-site-launch-checklist/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-samber-site-launch-checklist/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-samber-site-launch-checklist/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-samber-site-launch-checklist/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T17:43:27.691Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-samber-site-launch-checklist/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-samber-site-launch-checklist/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-samber-site-launch-checklist/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-samber-site-launch-checklist/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:39:22.927Z","emptyReason":null},"readme":"Skill: site-launch-checklist\n\nOwner: samber\n\nSummary: Pre-launch checklist for shipping a new website. Orchestrates analytics setup (GA4, PostHog, Google Search Console, Ahrefs), legal compliance, security headers and audit, SEO and GEO with keyword research validated against Google Trends (robots.txt, sitemaps, llms.txt, AI policy, schema markup, hreflang), copywriting consistency via a TONE.md and a humanizer pass in the matching language, OpenGraph and social previews, full favicon set with manifest, quality gates (Lighthouse, Core Web Vitals, WCAG accessibility, mobile testing), and setup of a weekly SEO agent. Use this skill whenever the user mentions launching a site/app, deploying a domain to production, pre-launch audit, shipping a marketing/docs/SaaS site or lead magnet, or says \"checklist for the site\", \"ready to ship\", \"before I go live\", \"audit before launch\", \"ready for prod\", or asks for a site review.\n\nTags: latest:1.2.0\n\nVersion history:\n\nv1.2.0 | 2026-08-21T12:13:49.125Z | auto\n\nsite-launch-checklist 1.2.0\n\n- Added new weekly SEO agent assets and references for improved SEO workflow.\n- Expanded companion SEO/marketing skill references, including new decision docs.\n- Updated compatibility notice to include Codex and clarify harnesses.\n- Improved user question handling: always uses the environment’s question tool when available.\n- Interaction and install flow clarified; wording streamlined.\n- Removed obsolete skill-card.md.\n\nv1.1.0 | 2026-06-10T15:19:37.099Z | auto\n\nsite-launch-checklist 1.1.0\n\n- Removed the obsolete skill-card.md file.\n- Updated SKILL.md metadata to version 1.1.0.\n- No functional or logic changes; documentation and structure cleanup only.\n\nv1.0.3 | 2026-05-22T01:21:11.678Z | auto\n\nsite-launch-checklist v1.0.3\n\n- Expanded the SKILL.md to include detailed, step-by-step interaction and confirmation logic for all phases of a pre-launch site checklist.\n- Added strict, checkpoint-based user input requirements at every decision point, with specific prompts for site type, migration, multilingual setup, analytics, legal policies, and browser tools.\n- Outlined a clear workflow for sub-skill and companion skill pack selection, ensuring only the needed subset is installed per site type and phase.\n- Clarified procedures for copywriting polishing, including defining a TONE.md and enforcing a mandatory humanizer pass in the site's main language.\n- Enhanced guidance on security, SEO/GEO, and quality audits via specialized skills and agents, all orchestrated interactively.\n\nArchive index:\n\nArchive v1.2.0: 14 files, 40479 bytes\n\nFiles: assets/weekly-seo-antigravity.md (2365b), assets/weekly-seo-claude-code.md (2068b), assets/weekly-seo-copilot-cli.md (2422b), assets/weekly-seo-gemini-cli.md (2428b), assets/weekly-seo-opencode.md (2298b), assets/weekly-seo-vibe-prompt.md (1743b), assets/weekly-seo-vibe.toml (265b), evals/evals.json (14250b), references/decisions.md (3988b), references/templates.md (10908b), references/weekly-seo-agent.md (12463b), skill-card.md (3486b), SKILL.md (31342b), _meta.json (140b)\n\nFile v1.2.0:SKILL.md\n\n---\nname: site-launch-checklist\ndescription: Pre-launch checklist for shipping a new website. Orchestrates analytics setup (GA4, PostHog, Google Search Console, Ahrefs), legal compliance, security headers and audit, SEO and GEO with keyword research validated against Google Trends (robots.txt, sitemaps, llms.txt, AI policy, schema markup, hreflang), copywriting consistency via a TONE.md and a humanizer pass in the matching language, OpenGraph and social previews, full favicon set with manifest, quality gates (Lighthouse, Core Web Vitals, WCAG accessibility, mobile testing), and setup of a weekly SEO agent. Use this skill whenever the user mentions launching a site/app, deploying a domain to production, pre-launch audit, shipping a marketing/docs/SaaS site or lead magnet, or says \"checklist for the site\", \"ready to ship\", \"before I go live\", \"audit before launch\", \"ready for prod\", or asks for a site review.\nlicense: MIT\ncompatibility: Designed for Claude Code, Codex or similar harness.\nuser-invocable: true\nmetadata:\n  author: samber\n  version: \"1.2.0\"\n  openclaw:\n    emoji: \"📊\"\n    homepage: https://github.com/samber/cc-skills\n    install:\n      - kind: npm\n        package: skills\n        bins: [skills]\n      - kind: brew\n        formula: jq\n        bins: [jq]\n    requires:\n      bins:\n        - curl\n        - npm\n        - npx\n        - jq\nallowed-tools: Read Edit Write Glob Grep Agent AskUserQuestion\n---\n\n**Questions:** Ask the user through the environment's question tool — never as plain-text prose. One question at a time, 2–4 tappable options, wait for the answer. If the environment has no question tool, ask in prose with the same options, one at a time.\n\n# Site Launch Checklist\n\nPre-launch audit and setup workflow for shipping a new website. Opinionated for Cloudflare DNS + Vercel hosting + PostHog + Legal context.\n\n## Interaction style (READ FIRST)\n\nThis skill is intentionally interactive. Ask aggressively instead of assuming. The user will tap, not type.\n\n**Always ask these questions at the start of a run** (one at a time, in this order):\n\n1. Site type: `doc-site` | `marketing/lead-gen` | `SaaS-app` | `training/paid-course` | `personal-portfolio`\n2. Migration: `greenfield-new-domain` | `migration-need-301-redirects` | `replacing-existing-on-same-domain`\n3. Multilingual: `single-locale` | `en` | `fr+en` | `other-multi`\n4. PostHog setup: `hogpost.samber.dev` | `set-up-new-proxy` | `skip-PostHog`\n5. AI scraper policy: `use-default-for-site-type` | `customize-per-bot` | `block-all`\n6. Browser tool available: `claude-chrome-extension` | `playwright` | `neither-skip-browser-checks`\n\n**Ask again at every decision point throughout the phases**, including:\n\n- Whether to install Sentry / BetterStack / Crisp (depends on site type, ask explicitly)\n- www vs apex canonical preference (most sites: apex; ask anyway)\n- Which AI bots to allow if user chose `customize-per-bot`\n- CSP tightness level: `strict-default-src-none` | `balanced-allow-self` | `permissive-for-marketing`\n- Whether to skip a phase entirely (e.g., skip Phase 3 if non-FR site)\n\nNever proceed past a decision point without explicit user input. Verbose checklists without checkpoints are not the goal.\n\n**Never install any MCP server or skill without explicit user confirmation.** Always ask via the question tool before running `npx skills add`, `claude mcp add`, or any equivalent install command — even when the skill selection workflow proposes a curated subset.\n\n## How to use this skill\n\n1. Run the start-of-session questions above.\n2. Walk the user through phases 1-10 in order. For each phase: a. List items, ask if any should be skipped. b. For each remaining item, run the verification command (see \"Verification tools\" below). c. Report pass/fail. On fail, ask the user if they want to fix now or queue for later.\n3. End with a status report grouped by phase, with blockers, recommended fixes, and optional improvements clearly separated.\n\n## Companion skills\n\nSix skill packs are useful for site launches. **Never install full multi-skill packs**. The actual subset to install is decided at invocation time based on the site type the user confirms.\n\n### Pack inventory\n\n| Pack | What it covers | Typically useful for |\n| --- | --- | --- |\n| `AgriciDaniel/claude-seo` | SEO + GEO + schema + hreflang + sitemaps audits, parallel sub-agents | All site types |\n| `addyosmani/web-quality-skills` | Lighthouse, Core Web Vitals, accessibility, performance, best practices | All site types |\n| `trailofbits/skills` | Security audit (OWASP, headers, dependencies) | All site types |\n| `aaron-he-zhu/seo-geo-claude-skills` | 20 SEO+GEO skills, CORE-EEAT + CITE frameworks, `/seo:` slash commands | Content-heavy sites, competitive niches |\n| `coreyhaines31/marketingskills` | ~30 marketing skills (CRO, copywriting, ads, popups, email, paywalls, etc.) | `marketing/lead-gen`, `SaaS-app`, `training/paid-course` |\n| `jonathimer/devmarketing-skills` | 33 developer-marketing skills (persona, docs-as-marketing, technical tutorials, etc.) | `doc-site`, `SaaS-app` for developers |\n\n### Skill selection workflow (run at session start)\n\nAfter the user confirms site type, for **each pack relevant to that site type**:\n\n1. **List available sub-skills**: `npx skills add owner/repo --list`\n2. **Propose a curated subset** based on site type and the phases this skill will execute. Match each phase's needs to specific sub-skills the listing returns.\n3. **Confirm with the user.** Use multi-select when the proposed list has more than 3 items, single-select (`install-as-proposed` | `let-me-modify` | `skip-this-pack`) otherwise.\n4. **Bulk install the agreed subset**: `npx skills add owner/repo --skill A B C`\n\nRules:\n\n- Sub-skill names live in the pack, not in this SKILL.md. Always query `--list` for the current state. Pack contents change.\n- Never run `npx skills add owner/repo` without `--skill` (that installs everything).\n- Site type → packs mapping (which packs to enumerate, sub-skills still selected per workflow):\n  - `doc-site`: claude-seo, web-quality-skills, trailofbits, seo-geo-claude-skills, devmarketing-skills\n  - `marketing/lead-gen`: claude-seo, web-quality-skills, trailofbits, seo-geo-claude-skills, marketingskills\n  - `SaaS-app`: all six\n  - `training/paid-course`: claude-seo, web-quality-skills, trailofbits, marketingskills\n  - `personal-portfolio`: claude-seo, web-quality-skills, trailofbits, seo-geo-claude-skills (lightweight subset)\n- If the user later requests a phase that needs a sub-skill not yet installed, run the workflow again for that single sub-skill rather than re-installing the whole subset.\n\nThis avoids importing 80+ skills the user does not need, avoids going stale on sub-skill names, and avoids overfitting to a single pack version.\n\nWhen delegating during a phase, do not duplicate work this skill orchestrates. Call the specialist with a narrow scope (e.g., \"run only the security headers sub-audit on URL X\").\n\n## Copywriting voice and humanizer pass\n\nEvery site has visible marketing copy (hero, features, CTAs, meta descriptions, OG descriptions, blog posts, 404 page text). Two layers of polish are mandatory before launch:\n\n### 1. Define `TONE.md` once per site\n\nAsk the user: \"Does this site already have a `TONE.md`?\" (`yes-already-exists` | `no-create-from-template` | `skip-use-default`).\n\nIf creating: write it to `.agents/TONE.md` or repo root `TONE.md`. See `references/templates.md` (section \"TONE.md template\") for the structure.\n\nTONE.md specifies: voice (terse, contrarian, etc.), forbidden patterns (e.g., \"delve\", \"crucial\", em dashes, AI-sounding openers), sentence length preference, audience reading level, examples of good and bad sentences from the user's own writing.\n\n### 2. Run a humanizer pass in the matching language\n\nAfter every drafting step (whether by a copywriting skill, by hand, or by Claude directly), run a humanizer to strip AI patterns.\n\nAsk the user for the site's primary audience language at the start of the session if not already known:\n\n- `english-global` → `npx skills add https://github.com/blader/humanizer --skill humanizer`\n- `french` → use `samber/humaniseur-fr` (custom French humanizer) or equivalent French-tuned skill\n- `other` → install matching humanizer if available; otherwise the skill writes a short language-specific anti-pattern checklist inline\n\nApply the humanizer to: hero copy, feature descriptions, CTA buttons, meta descriptions, OG/Twitter card descriptions, blog posts, email signup confirmations, 404 page text. Skip for legal pages (mentions légales, CGV) since they have rigid wording requirements.\n\n### 3. Always reference TONE.md when invoking copywriting skills\n\nWhen delegating to any copywriting or content-writing sub-skill (selected at invocation per the skill selection workflow), include `TONE.md` in the prompt context. Pass voice constraints explicitly: \"Follow `.agents/TONE.md`. Avoid the listed patterns. Apply the humanizer after drafting.\"\n\n## Browser interaction preference\n\nMany checks require a real browser (Lighthouse runs, securityheaders.com scan, opengraph.xyz validation, Twitter card validator, mobile viewport, screen reader smoke, Network tab inspection).\n\n**Always prefer the Claude Chrome extension.** Fall back to Playwright only if the Chrome extension is unavailable. If neither is available, ask the user whether to skip browser checks entirely or wait until they enable one.\n\n## Verification tools\n\nMost checks are doable from the command line without third-party services. Use these tools inline at every phase. Don't trust panels in Cloudflare/Vercel/Google dashboards alone, verify with curl.\n\n**DNS (Phase 1):**\n\n```bash\ndig +short A example.com                          # A record\ndig +short AAAA example.com                       # AAAA (IPv6)\ndig +short MX example.com                         # MX (mail)\ndig +short TXT example.com                        # SPF + verification TXT\ndig +short TXT _dmarc.example.com                 # DMARC\ndig +short TXT default._domainkey.example.com     # DKIM (selector varies)\ndig +short CAA example.com                        # CAA\ndig +dnssec example.com | grep RRSIG              # DNSSEC active\n```\n\n**TLS / HTTPS (Phase 1):**\n\n```bash\ncurl -sIL https://example.com | head             # follow redirects\ncurl -sI https://www.example.com                 # check www handling\nopenssl s_client -showcerts -connect example.com:443 < /dev/null 2>/dev/null | openssl x509 -noout -dates\n```\n\n**Headers (Phase 4):**\n\n```bash\ncurl -sI https://example.com | grep -iE 'content-security-policy|strict-transport-security|x-frame-options|x-content-type-options|referrer-policy|permissions-policy'\n# Full header dump:\ncurl -sI https://example.com\n# External graders:\ncurl -s \"https://api.securityheaders.com/?q=https://example.com&followRedirects=on&hide=on\" -I | grep -i 'x-grade'\n```\n\n**SEO files (Phase 5):**\n\n```bash\ncurl -s https://example.com/robots.txt\ncurl -sI https://example.com/sitemap.xml\ncurl -s https://example.com/sitemap.xml | head -40\ncurl -s https://example.com/llms.txt\n# Schema (JSON-LD):\ncurl -s https://example.com/ | grep -A 50 'application/ld+json'\n# hreflang:\ncurl -s https://example.com/ | grep -i hreflang\n```\n\n**Open Graph & social (Phase 6):**\n\n```bash\ncurl -s https://example.com/page | grep -iE 'og:|twitter:|<title|name=\"description\"'\n```\n\n**Favicons & manifest (Phase 7):**\n\n```bash\ncurl -sI https://example.com/favicon.ico\ncurl -sI https://example.com/favicon.svg\ncurl -sI https://example.com/apple-touch-icon.png\ncurl -s https://example.com/manifest.json | jq .\n```\n\n**404 / 500 / redirects:**\n\n```bash\ncurl -sI https://example.com/this-does-not-exist\ncurl -sIL https://example.com/old-url     # verify 301 chain\n```\n\nAlways run the relevant command, paste the output to the user when reporting, then ask whether to fix immediately or queue.\n\n---\n\n## Phase 1: Domain & Infrastructure\n\nMost of this is one-click via Cloudflare's dashboard if the domain is on Cloudflare.\n\nAsk first: \"Is the domain already on Cloudflare with the standard config from previous launches?\" (`yes-standard` | `yes-needs-review` | `no-fresh-setup`)\n\nChecklist:\n\n- [ ] Cloudflare: proxy ON for apex + www, TLS 1.3 minimum, \"Always Use HTTPS\" enabled, HSTS preload enabled in Cloudflare SSL/TLS settings\n- [ ] DNS A/AAAA or CNAME pointing to Vercel (verify with `dig +short A example.com`)\n- [ ] MX records for Google Workspace (verify with `dig +short MX example.com`)\n- [ ] SPF, DKIM, DMARC records (verify all 3 with the dig commands above)\n- [ ] CAA records restricting cert issuance (verify with `dig +short CAA example.com`)\n- [ ] DNSSEC enabled at registrar level (verify with `dig +dnssec`)\n- [ ] Vercel: project linked to repo, prod + preview env vars set, custom domain attached, prod and preview aliases correct\n- [ ] Decide www vs apex canonical, configure 308 redirect for the non-canonical (verify with `curl -sIL https://www.example.com`)\n- [ ] Custom 404 page renders (verify with `curl -sI https://example.com/does-not-exist`)\n- [ ] Custom 500 page exists (cannot easily verify without forcing an error, ask user)\n- [ ] If migration: 301 redirect map for every old URL (loop verification with `curl -sIL` per URL)\n\n### Backups\n\nIf you don't configure backups at launch, you never will. Do it now.\n\nAsk the user: \"Which data stores does this app write to?\" (`database-only` | `database-plus-file-storage` | `file-storage-only` | `stateless-no-persistent-data`). If `stateless-no-persistent-data`, skip this section.\n\n**Database:**\n\n- [ ] Automated daily backups enabled at the provider level (Neon, Supabase, PlanetScale, Railway, RDS — each has a one-click toggle). Verify by opening the backup panel and confirming the last backup timestamp is recent.\n- [ ] Retention policy set to ≥30 days\n- [ ] Point-in-time recovery (PITR) enabled if available (Neon, Supabase, RDS all support it)\n- [ ] Off-site copy: if the provider stores backups in the same region as the primary, configure cross-region replication or a nightly export to a separate storage account (S3, R2, GCS)\n- [ ] **Restore drill performed before launch**: pick a recent backup, restore to a staging database, verify row counts and a sample query. A backup you haven't tested is not a backup.\n\n**File storage (if applicable — S3, R2, GCS, Cloudflare Images):**\n\n- [ ] Versioning enabled on the primary bucket\n- [ ] Cross-region replication or a scheduled sync to a secondary bucket. Backblaze B2 is a cheap, reliable option for off-site copies (significantly cheaper than S3/GCS egress). Use `rclone` to sync from S3/R2/GCS → B2 on a daily cron.\n- [ ] Lifecycle rule: transition old versions to cheaper storage after 30 days, delete after 90 days (adjust to cost tolerance)\n\n**Secrets / environment variables:**\n\n- [ ] All env vars documented and stored in a secrets manager (1Password, Doppler, Vault, or equivalent). Not in a `.env` file on someone's laptop.\n- [ ] Verify: if every engineer's machine burned tonight, could a new team member restore prod from scratch using only the secrets manager + git?\n\n**Monitoring:**\n\n- [ ] Set up an alert (email or Slack) if the daily backup job fails. Most providers support this natively; configure it before closing the backup panel.\n\n---\n\n## Phase 2: Analytics & Observability\n\nMost third-party integrations are one-click via Cloudflare or Vercel.\n\n**For the conditional tools (Crisp, Sentry, BetterStack), ask the user** to confirm per site type. See `references/decisions.md` for the observability tier matrix.\n\n**Always-on:**\n\n- [ ] Google Analytics 4: property created, measurement ID embedded, gated behind CNIL consent\n- [ ] PostHog: based on user's earlier answer:\n  - If `hogpost.samber.dev`: configure client with `api_host: \"https://hogpost.samber.dev\"` and verify CORS allows the new domain (test with browser console or `curl -H \"Origin: https://newsite.com\" -I https://hogpost.samber.dev/decide`)\n  - If `set-up-new-proxy`: add path rewrite in `next.config.js` to `us.i.posthog.com` and `us-assets.i.posthog.com`, init client with `api_host: \"/ingest\"`\n  - If `skip-PostHog`: skip\n- [ ] Google Search Console: site verified (DNS TXT or HTML file), sitemap submitted\n- [ ] Bing Webmaster Tools: site verified, sitemap submitted, IndexNow key file at `/{key}.txt` on root (verify with `curl -sI https://example.com/{key}.txt`)\n- [ ] Ahrefs: site added to dashboard for tracking\n- [ ] Add the site to the internal stats spreadsheet (PostHog properties registry + GitHub Sponsors tracking sheet if applicable)\n\n**Brand monitoring (Google Alerts):**\n\nFor each alert, use these settings: **Frequency**: once a day | **Sources**: Automatic | **How many**: All results | **Region**: Any region\n\nSet up one alert per keyword via alerts.google.com:\n\n- [ ] Domain name (e.g., `example.com`)\n- [ ] Brand or product name (quoted if multi-word, e.g., `\"My Brand\"`)\n- [ ] Key feature or library names if the site documents a project\n- [ ] Competitor brand names (optional — ask user: `yes-monitor-competitors` | `skip`)\n\nAsk the user: \"Which additional keywords to monitor?\" (`product-name-only` | `domain-plus-brand` | `full-set-with-competitors` | `custom-list`)\n\n**Developer community monitoring (F5bot) — for `doc-site` and `SaaS-app` targeting developers:**\n\nF5bot (f5bot.com) monitors Reddit, Hacker News, and Lobste.rs for keyword mentions and sends email alerts. Free, no API required.\n\nSet up one keyword per line at f5bot.com/add:\n\n- [ ] Brand or product name\n- [ ] Domain name (catches link shares)\n- [ ] Key feature or library names\n- [ ] Common misspellings if applicable\n\n**Competitor analysis (`marketing/lead-gen`, `SaaS-app`, `training/paid-course` only):**\n\nBefore writing copy, setting up ads, or planning content, run a competitor analysis to understand what is already working in the market — positioning, messaging angles, CTA patterns, pricing presentation, and content strategy.\n\nUse a deep research tool or a competitor analysis skill if one is available in the toolchain. Ask:\n\n- \"Do you already have competitor names/URLs to analyze?\" (`yes-provide-list` | `no-discover-for-me` | `skip`)\n- If `yes-provide-list`: ask the user to paste 2-5 names or URLs (free text)\n- \"What are we looking to extract?\" (`positioning-and-messaging` | `pricing-strategy` | `content-and-seo` | `full-spectrum`)\n\nFeed the output into:\n\n- Phase 5 keyword strategy (target queries they rank for but you can outrank or flank)\n- `TONE.md` voice calibration (deliberately differentiate from the dominant tone in the category)\n- Phase 6 OG copy and CTA language (borrow proven frames, don't clone verbatim)\n- Copywriting sub-skills invoked later (pass the competitor snapshot as context)\n\n**Conditional (ask user, default per site type from `references/decisions.md`):**\n\n- [ ] Crisp\n- [ ] Sentry\n- [ ] BetterStack\n\n---\n\n## Phase 3: Legal & Compliance (FR)\n\nAsk first: \"Is this site subject to French law?\" (`yes-FR-operator-or-audience` | `no-EU-only` | `no-non-EU`). If no, ask whether GDPR or equivalent applies and adjust.\n\nFor FR sites:\n\n- [ ] Mentions légales page (mandatory, fines up to 75k€ per omission)\n- [ ] CGV (Conditions Générales de Vente) if commercial activity\n- [ ] Privacy policy\n- [ ] Terms of service\n- [ ] CNIL-compliant cookie consent that **gates** GA4, PostHog, Crisp, Sentry script loading (not just a banner that always loads trackers). Use a CMP (Axeptio, Tarteaucitron, or custom). Verify with browser Network tab: no tracker fires before explicit consent.\n\n---\n\n## Phase 4: Security\n\nDelegate the deep audit to `trailofbits/skills`. The items below are the must-pass checklist.\n\nAsk first: CSP tightness level (`strict-default-src-none` | `balanced-allow-self` | `permissive-for-marketing`). See `references/templates.md` for the CSP template per level.\n\n- [ ] CSP: target chosen tightness level. No `'unsafe-inline'` for scripts (use nonces). Verify with `curl -sI ... | grep -i content-security-policy`.\n- [ ] HSTS: `max-age=31536000; includeSubDomains; preload`. Submit to hstspreload.org. Verify with `curl -sI ... | grep -i strict-transport`.\n- [ ] X-Frame-Options: `DENY`\n- [ ] X-Content-Type-Options: `nosniff`\n- [ ] Referrer-Policy: `strict-origin-when-cross-origin`\n- [ ] Permissions-Policy: deny camera, microphone, geolocation, payment unless used\n- [ ] Run all headers in one go: `curl -sI https://example.com | grep -iE 'content-security|strict-transport|x-frame|x-content-type|referrer-policy|permissions-policy'`\n- [ ] securityheaders.com: target A+ (verify via Claude Chrome extension or `curl https://securityheaders.com/?q=URL` and parse)\n- [ ] observatory.mozilla.org: target 90+ (via Chrome extension)\n- [ ] Run `trailofbits/skills` security audit on the codebase\n- [ ] Verify no leaked secrets in client bundle: open Chrome DevTools Network tab via Claude Chrome extension, grep response bodies for `sk_`, `pk_`, `AKIA`, `ghp_`, `Bearer`\n\n---\n\n## Phase 5: SEO & GEO\n\nDelegate the full audit to `AgriciDaniel/claude-seo`. The items below are the orchestration list.\n\nSee `references/templates.md` for `robots.txt`, `llms.txt`, and `manifest.json` templates. See `references/decisions.md` for the AI scraper policy matrix by site type.\n\n- [ ] `/robots.txt` present, references sitemap (verify with `curl -s https://example.com/robots.txt`)\n- [ ] `/sitemap.xml` present, valid (verify with `curl -s https://example.com/sitemap.xml | head -40`). Sitemap-index with per-language sitemaps if multilingual.\n- [ ] `/llms.txt` present (per llmstxt.org spec, verify with `curl -s https://example.com/llms.txt`)\n- [ ] AI scraper policy encoded in `robots.txt`. Apply the matrix from `references/decisions.md` based on site type, then **ask via the question tool to confirm each non-default decision** — this ships in a public file, get it right before it's crawled.\n- [ ] Schema markup (JSON-LD): `Organization` + `WebSite` + `BreadcrumbList` site-wide; per-page types where applicable (`SoftwareApplication` for lib homepages, `Article` for blog posts, `FAQPage` for FAQs, `Person` for author bio). Verify with `curl -s URL | grep -A 50 'application/ld+json'`. Validate structured data via **Google Rich Results Test** (<https://search.google.com/test/rich-results>) and **Schema.org Validator** (<https://validator.schema.org>) — Rich Results Test checks eligibility for rich snippets; Schema.org Validator catches spec violations that Google may silently ignore.\n- [ ] Meta tags per page: unique `<title>` (50-60 chars), unique `<meta description>` (150-160 chars), `<link rel=\"canonical\">`, `<meta name=\"robots\">` if needed\n- [ ] `hreflang` tags on every page if multilingual (every language version declares all alternates including self). Verify with `curl -s URL | grep -i hreflang`.\n- [ ] **Keyword analysis using both Google Trends and Ahrefs** (they answer different questions, not interchangeable):\n  - **Google Trends** (trends.google.com): trajectory (rising vs declining), geographic distribution (especially FR vs international split), seasonal patterns, related queries breakout, head-to-head comparison of 2-5 candidate keywords. Use Trends to **validate direction and timing** of the SEO bet.\n  - **Exploding Topics** (explodingtopics.com): surfaces emerging trends weeks or months before they peak in Google Trends. Use to identify rising queries before competition solidifies and to validate that target keywords aren't already on the decline.\n  - **Answer The Public** (answerthepublic.com/en): maps search questions, comparisons, and related queries around a seed keyword. Use to uncover long-tail intent clusters, populate FAQ schema, and identify content gaps.\n  - **Ahrefs Keywords Explorer**: monthly volume, keyword difficulty, SERP analysis, CPC, parent topic, traffic potential. Use Ahrefs to **size the opportunity** in absolute terms.\n  - Combined output: a ranked shortlist of 3-5 target queries per page, with rationale (volume × difficulty × trajectory × intent match).\n  - Delegate to whichever keyword-research sub-skill was installed at session start (selected from the installed packs via the skill selection workflow; typical sources are the SEO+GEO and marketing packs).\n- [ ] **AI visibility audit via productrank.ai**: open productrank.ai in a browser, submit multiple category or product searches, run the full AI SEO report. It audits how the site appears in AI-generated answers (ChatGPT, Perplexity, Gemini, Claude). Flag any zero-visibility categories and surface content gaps the AI graders identify.\n- [ ] Typo and grammar pass on all visible text content\n- [ ] Backlink profile audit: run **Ahrefs Backlink Checker** and **Moz Link Explorer** to assess domain authority and surface toxic or broken inbound links before launch — especially critical on migrations to ensure old-domain equity transfers correctly\n- [ ] Internal linking audit: every important page reachable in ≤3 clicks from the homepage\n\n---\n\n## Phase 6: Open Graph & Social Preview\n\nVerify all OG and Twitter tags with: `curl -s URL | grep -iE 'og:|twitter:'`\n\n- [ ] `og:title`, `og:description`, `og:url`, `og:type`, `og:site_name`\n- [ ] `og:image` 1200×630px, absolute URL, `og:image:width` and `og:image:height` declared, `og:image:alt` set\n- [ ] **Per-page `og:image`**, not one global. For doc sites: generate dynamically from page title. For blog posts: per-article custom image.\n- [ ] `og:locale` + `og:locale:alternate` for each language if multilingual\n- [ ] Twitter Cards: `twitter:card=summary_large_image`, `twitter:title`, `twitter:description`, `twitter:image`, `twitter:site` (handle)\n- [ ] Validate with opengraph.xyz (covers FB, LinkedIn, Slack, Discord, WhatsApp previews) via Claude Chrome extension\n- [ ] Validate with Twitter's card validator\n- [ ] Manual check: paste URL in a LinkedIn DM, a Slack channel, a Discord, an iMessage. Preview must render correctly in all.\n\n---\n\n## Phase 7: Favicons & Web Manifest\n\nSee `references/templates.md` for the `manifest.json` template.\n\nGenerate from a single 1024×1024 source PNG using realfavicongenerator.net or favicon.io.\n\n**Minimum modern set:**\n\n- [ ] `/favicon.ico` (multi-res 16/32/48). Verify with `curl -sI https://example.com/favicon.ico`.\n- [ ] `/favicon.svg` with embedded `<style>@media (prefers-color-scheme: dark) { ... }</style>` for dark mode. Verify with `curl -sI https://example.com/favicon.svg`.\n- [ ] `/favicon-96x96.png` (PNG fallback)\n- [ ] `/apple-touch-icon.png` 180×180px, no transparency, opaque background. Verify with `curl -sI`.\n- [ ] `/web-app-manifest-192x192.png` (Android PWA icon)\n- [ ] `/web-app-manifest-512x512.png` (Android splash)\n- [ ] `/manifest.json` referencing both PNGs, with `theme_color`, `background_color`, `name`, `short_name`, `display`. Verify with `curl -s https://example.com/manifest.json | jq .`.\n\n**Skip (deprecated):**\n\n- `mstile-*.png` (Windows tiles)\n- `safari-pinned-tab.svg` (deprecated since macOS Big Sur)\n- `favicon-16x16.png` / `favicon-32x32.png` (covered by `.ico` and `.svg`)\n\n**HTML head verification:**\n\n```bash\ncurl -s https://example.com/ | grep -iE 'rel=\"icon\"|rel=\"apple-touch-icon\"|rel=\"manifest\"'\n```\n\n---\n\n## Phase 8: Quality Gates\n\nDelegate to `addyosmani/web-quality-skills`. The skill covers 150+ Lighthouse audits across performance, accessibility, SEO, and best practices.\n\n- [ ] **Unlighthouse site-wide crawl**: `npx unlighthouse --site {site}` — crawls all pages and runs Lighthouse on each. Surface pages below 90 on any axis before the per-URL checks.\n- [ ] Lighthouse all 4 axes, mobile mode: target ≥90 on each (perf, a11y, best practices, SEO)\n- [ ] Lighthouse all 4 axes, desktop mode: target ≥95 on each\n- [ ] Core Web Vitals field data (CrUX via PageSpeed Insights): LCP < 2.5s, INP < 200ms, CLS < 0.1, on both mobile and desktop\n- [ ] Accessibility (WCAG 2.2 AA via `web-quality-skills`): keyboard nav works for every interactive element, focus rings visible, color contrast ≥4.5:1 for text, all images have `alt`, heading hierarchy is monotonic (H1 → H2 → H3), ARIA labels on icon-only buttons\n- [ ] Real mobile device test (not just devtools emulator). Use Claude Chrome extension on mobile viewport on a real device or BrowserStack.\n- [ ] Cross-browser smoke test: Chrome, Safari, Firefox latest stable\n- [ ] Print stylesheet sanity (Cmd+P should not break layout)\n\n---\n\n## Phase 9: Ecosystem Cross-linking\n\nInternal cross-linking between owned properties. High-leverage SEO action for any multi-domain owner.\n\nAsk the user: \"List the other domains in your ecosystem that are topically relevant to this new site.\" Then for each one:\n\n- [ ] Add a link from the existing site (footer / nav / \"other projects\" section) to the new site, where topically relevant\n- [ ] Add a link to the new site in the README of the matching GitHub repo, if it documents a library\n- [ ] Verify reciprocal links: every link added points back where appropriate\n- [ ] If the new site documents a Go lib, link from related lib docs\n\nDo not over-link. Only cross-link where topically relevant. A doc site for a logging lib should not link to a personal blog about cycling.\n\n---\n\n## Phase 10: Set up weekly SEO maintenance sub-agent\n\nAfter launch, set up a scheduled background agent, such as Hermes or Claude Cowork Routine, that runs weekly to monitor SEO health and surface action items.\n\nSee `references/weekly-seo-agent.md` for the full agent definition, with a concrete equivalent for each harness — copy the block matching your environment into the location it specifies, in the site's repo (or a dedicated ops repo). The agent uses these MCP connectors (or their equivalent API calls):\n\n- Ahrefs MCP (backlinks, rankings, keywords)\n- PostHog MCP (analytics correlation, AI bot traffic)\n- Web search (SERP monitoring, competitor checks)\n- Google Search Console (via community MCP or `curl` with service account credentials)\n\n**Ask via the question tool** before creating the file: \"Set up the weekly SEO agent now?\" (`yes-create-agent-file` | `yes-but-defer` | `skip-for-now`).\n\nWhen MCP are not available, use Claude for Chrome extension.\n\n---\n\n## Output format\n\nAt the end of a full run, output a status report grouped by phase:\n\n```\nPhase 1: Domain & Infrastructure  [9/10 pass]\n  ✓ Cloudflare proxy on\n  ✓ DNS records configured\n  ...\n  ✗ DMARC missing. Fix: add TXT record at _dmarc.example.com with policy v=DMARC1; p=quarantine;...\n\nPhase 2: Analytics & Observability  [6/7 pass]\n  ...\n```\n\nFollowed by three lists, in order:\n\n1. **Blockers** (must fix before launch)\n2. **Recommended fixes** (should fix before announcing)\n3. **Optional improvements** (post-launch)\n\nEnd by asking: \"Which list do you want to tackle next?\" (`blockers` | `recommended` | `optional` | `done-for-now`).\n\n---\n\n## References\n\n- `references/decisions.md`: AI scraper policy matrix by site type, observability tier matrix\n- `references/templates.md`: robots.txt, llms.txt, manifest.json, CSP templates per tightness level, security headers reference\n- `references/weekly-seo-agent.md`: Full definition of the weekly SEO maintenance sub-agent (MCPs, tasks, output format)\n- `assets/weekly-seo-*.md`, `assets/weekly-seo-vibe.toml`: per-harness agent-definition files linked from `references/weekly-seo-agent.md` — copy the one matching your harness\n\nFile v1.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn72rhnkwjfeex9wr1n7y24qa983cjn3\",\n  \"slug\": \"site-launch-checklist\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1787314429125\n}\n\nFile v1.2.0:references/decisions.md\n\n# Decisions and matrices\n\nRepeating decisions for site launches. Apply the matrix based on the site type the user confirmed at the start of the session. When a decision is ambiguous or borderline, ask through the question tool, one at a time, rather than assuming.\n\n## AI scraper policy by site type\n\nDecide which AI training and AI-search crawlers to allow per site type. Encode the decision in `robots.txt` (see `templates.md`).\n\n### Marketing / lead-gen page (consulting, training landing)\n\nAllow all AI scrapers. Your conversion copy is intellectual property; training it into LLMs that may recommend competitors is anti-value. But AI citations on a sales page is good.\n\n### Paid course / training page\n\nBlock all. Content is the product.\n\n### Personal portfolio / personal blog\n\nAllow the citing crawlers (ClaudeBot, GPTBot, PerplexityBot, Google-Extended). Useful for \"who is X\" or \"what does X work on\" queries.\n\n### SaaS app\n\n- App subdomain (e.g., app.example.com): block all AI scrapers. The app is gated, no value in scraping.\n- Landing / marketing subdomain: apply the marketing rules above.\n\n### Default when site type is unclear\n\nBlock all. Ask the user. Better to surface the decision than to silently expose content to crawlers.\n\n---\n\n## Observability tier by site type\n\nDecide which analytics and observability tools to install. Always confirm conditional tools with the user.\n\n### Doc site / lib homepage\n\n| Tool | Install? |\n| --- | --- |\n| GA4 | Yes |\n| PostHog (via hogpost.samber.dev or new proxy) | Yes |\n| Google Search Console | Yes |\n| Bing Webmaster + IndexNow | Yes |\n| Ahrefs | Yes |\n| Crisp | **No** (doc readers don't chat, it tanks Lighthouse) |\n| Sentry | **No** (static, no app logic to crash) |\n| BetterStack | **No** (Vercel uptime is enough) |\n\n### Marketing / lead-gen\n\nAll of the doc-site tools, plus:\n\n| Tool        | Install?                                       |\n| ----------- | ---------------------------------------------- |\n| Crisp       | Yes (conversion intent)                        |\n| Sentry      | Yes if there are forms or interactive elements |\n| BetterStack | Only if you publish an SLA                     |\n\n### SaaS app\n\nAll of the above, plus:\n\n| Tool              | Install?                       |\n| ----------------- | ------------------------------ |\n| Sentry            | **Mandatory**                  |\n| BetterStack       | Yes, with a public status page |\n| Crisp or Intercom | Yes                            |\n\n### Personal portfolio\n\n| Tool        | Install? |\n| ----------- | -------- |\n| GA4         | Yes      |\n| PostHog     | Yes      |\n| GSC         | Yes      |\n| Ahrefs      | Optional |\n| Crisp       | No       |\n| Sentry      | No       |\n| BetterStack | No       |\n\n---\n\n## www vs apex canonical\n\nDefault: **apex is canonical, www redirects to apex via 308**.\n\nException: if the site is hosted on a platform that requires CNAME (which cannot be set on apex per DNS RFCs), the platform's flattening / ALIAS / ANAME feature is used. Cloudflare handles this transparently with CNAME flattening, so apex remains canonical.\n\nVerify with:\n\n```bash\ncurl -sIL https://www.example.com\n# Expect: 308 → https://example.com\n```\n\n---\n\n## CSP tightness level by site type\n\nThree levels. Ask the user to pick one at the start of Phase 4.\n\n### `strict-default-src-none`\n\nFor doc sites, personal portfolio, SaaS app. Whitelist every source explicitly. No `'unsafe-inline'`. Use nonces for any required inline scripts.\n\n### `balanced-allow-self`\n\nFor marketing pages with embeds (YouTube, Calendly, etc.). `default-src 'self'`, then allow specific third parties.\n\n### `permissive-for-marketing`\n\nLast resort for legacy marketing pages with many third-party scripts (HubSpot, Drift, etc.). Document why and plan to tighten.\n\nSee `templates.md` for the actual CSP strings per level.\n\n---\n\n## When a decision is unclear\n\nAlways default to asking, with the matrix options as tappable choices. Never silently apply a guess.\n\nFile v1.2.0:references/templates.md\n\n# Templates\n\nFile and header templates for site launches. Apply per the matrices in `decisions.md`.\n\n## robots.txt\n\n### Template: doc site for OSS lib (allow AI scrapers)\n\n```\nUser-agent: *\nAllow: /\n\nSitemap: https://EXAMPLE.com/sitemap.xml\n\n# AI scrapers (per decisions.md: doc-site policy)\nUser-agent: GPTBot\nAllow: /\n\nUser-agent: ChatGPT-User\nAllow: /\n\nUser-agent: ClaudeBot\nAllow: /\n\nUser-agent: anthropic-ai\nAllow: /\n\nUser-agent: PerplexityBot\nAllow: /\n\nUser-agent: Google-Extended\nAllow: /\n\nUser-agent: CCBot\nAllow: /\n\nUser-agent: Applebot-Extended\nAllow: /\n\n# Blocked low-value scrapers\nUser-agent: Bytespider\nDisallow: /\n\nUser-agent: Amazonbot\nDisallow: /\n```\n\n### Template: marketing / lead-gen (block all AI scrapers)\n\n```\nUser-agent: *\nAllow: /\n\nSitemap: https://EXAMPLE.com/sitemap.xml\n\n# Block all AI scrapers (per decisions.md: marketing policy)\nUser-agent: GPTBot\nDisallow: /\n\nUser-agent: ChatGPT-User\nDisallow: /\n\nUser-agent: ClaudeBot\nDisallow: /\n\nUser-agent: anthropic-ai\nDisallow: /\n\nUser-agent: PerplexityBot\nDisallow: /\n\nUser-agent: Google-Extended\nDisallow: /\n\nUser-agent: CCBot\nDisallow: /\n\nUser-agent: Applebot-Extended\nDisallow: /\n\nUser-agent: Bytespider\nDisallow: /\n\nUser-agent: Amazonbot\nDisallow: /\n```\n\nNote: regular search engine crawlers (Googlebot, Bingbot) are not in the AI bot list and remain governed by the `User-agent: *` rule.\n\n---\n\n## llms.txt\n\nPer llmstxt.org spec. Place at root.\n\n```\n# Project Name\n\n> One-line description of the project, written for an LLM consumer.\n\nMarkdown paragraph giving more context on what the project does, who it's for, and why it exists.\n\n## Docs\n\n- [Getting started](https://example.com/docs/getting-started): how to install and run the first example\n- [API reference](https://example.com/docs/api): full API documentation\n- [Examples](https://example.com/docs/examples): working code samples\n\n## Optional\n\n- [Changelog](https://example.com/changelog): version history\n- [Contributing](https://github.com/owner/repo/blob/main/CONTRIBUTING.md): how to contribute\n```\n\nFor richer LLM consumption, also publish `llms-full.txt` with the full content of all documentation pages concatenated.\n\n---\n\n## manifest.json\n\nMinimum modern PWA manifest. Place at root or `/manifest.json`.\n\n```json\n{\n  \"name\": \"Site Full Name\",\n  \"short_name\": \"Site\",\n  \"description\": \"One-line description matching meta description.\",\n  \"start_url\": \"/\",\n  \"display\": \"standalone\",\n  \"background_color\": \"#ffffff\",\n  \"theme_color\": \"#000000\",\n  \"icons\": [\n    {\n      \"src\": \"/web-app-manifest-192x192.png\",\n      \"sizes\": \"192x192\",\n      \"type\": \"image/png\",\n      \"purpose\": \"maskable\"\n    },\n    {\n      \"src\": \"/web-app-manifest-512x512.png\",\n      \"sizes\": \"512x512\",\n      \"type\": \"image/png\",\n      \"purpose\": \"maskable\"\n    },\n    {\n      \"src\": \"/web-app-manifest-192x192.png\",\n      \"sizes\": \"192x192\",\n      \"type\": \"image/png\",\n      \"purpose\": \"any\"\n    },\n    {\n      \"src\": \"/web-app-manifest-512x512.png\",\n      \"sizes\": \"512x512\",\n      \"type\": \"image/png\",\n      \"purpose\": \"any\"\n    }\n  ]\n}\n```\n\nHTML `<head>` references:\n\n```html\n<link rel=\"icon\" href=\"/favicon.ico\" sizes=\"any\" />\n<link rel=\"icon\" type=\"image/svg+xml\" href=\"/favicon.svg\" />\n<link rel=\"apple-touch-icon\" href=\"/apple-touch-icon.png\" />\n<link rel=\"manifest\" href=\"/manifest.json\" />\n<meta name=\"theme-color\" content=\"#000000\" />\n```\n\n---\n\n## CSP templates\n\nThree tightness levels. Pick per the matrix in `decisions.md`.\n\n### `strict-default-src-none`\n\nFor doc sites, personal portfolio, SaaS apps with bundled assets only.\n\n```\ndefault-src 'none';\nscript-src 'self' 'nonce-{NONCE}' https://hogpost.samber.dev;\nstyle-src 'self' 'unsafe-inline';\nimg-src 'self' data: https:;\nfont-src 'self' data:;\nconnect-src 'self' https://hogpost.samber.dev https://eu.i.posthog.com;\nmanifest-src 'self';\nbase-uri 'self';\nform-action 'self';\nframe-ancestors 'none';\nobject-src 'none';\nupgrade-insecure-requests;\n```\n\nNotes:\n\n- `style-src 'unsafe-inline'` is unfortunately required by most modern frameworks (Tailwind in dev, styled-components, etc.). Tighten with hashes if feasible.\n- Replace `{NONCE}` with a per-request random value generated server-side (Next.js middleware can do this).\n- `connect-src` includes `eu.i.posthog.com` as a fallback if `hogpost.samber.dev` proxy is unavailable.\n\n### `balanced-allow-self`\n\nFor marketing pages with embeds.\n\n```\ndefault-src 'self';\nscript-src 'self' 'nonce-{NONCE}' https://hogpost.samber.dev https://www.youtube.com https://assets.calendly.com;\nstyle-src 'self' 'unsafe-inline' https://assets.calendly.com;\nimg-src 'self' data: https:;\nfont-src 'self' data:;\nconnect-src 'self' https://hogpost.samber.dev https://*.calendly.com;\nframe-src 'self' https://www.youtube.com https://calendly.com;\nframe-ancestors 'none';\nobject-src 'none';\nupgrade-insecure-requests;\n```\n\nAdjust embed origins as needed.\n\n### `permissive-for-marketing`\n\nLegacy fallback. Add a TODO comment in the codebase to tighten in the next iteration.\n\n```\ndefault-src 'self' https:;\nscript-src 'self' 'unsafe-inline' 'unsafe-eval' https:;\nstyle-src 'self' 'unsafe-inline' https:;\nimg-src 'self' data: https:;\nfont-src 'self' data: https:;\nconnect-src 'self' https:;\nframe-ancestors 'none';\nupgrade-insecure-requests;\n```\n\n---\n\n## Full security headers reference\n\nApply all of these in addition to CSP. Add to Vercel's `vercel.json` or Next.js `next.config.js` `headers()`.\n\n```json\n{\n  \"headers\": [\n    {\n      \"source\": \"/(.*)\",\n      \"headers\": [\n        {\n          \"key\": \"Strict-Transport-Security\",\n          \"value\": \"max-age=31536000; includeSubDomains; preload\"\n        },\n        { \"key\": \"X-Content-Type-Options\", \"value\": \"nosniff\" },\n        { \"key\": \"X-Frame-Options\", \"value\": \"DENY\" },\n        {\n          \"key\": \"Referrer-Policy\",\n          \"value\": \"strict-origin-when-cross-origin\"\n        },\n        {\n          \"key\": \"Permissions-Policy\",\n          \"value\": \"camera=(), microphone=(), geolocation=(), payment=(), usb=(), magnetometer=(), gyroscope=()\"\n        },\n        { \"key\": \"Cross-Origin-Opener-Policy\", \"value\": \"same-origin\" },\n        { \"key\": \"Cross-Origin-Embedder-Policy\", \"value\": \"credentialless\" },\n        { \"key\": \"Cross-Origin-Resource-Policy\", \"value\": \"same-origin\" }\n      ]\n    }\n  ]\n}\n```\n\nNotes:\n\n- `Cross-Origin-Embedder-Policy: credentialless` is safer than `require-corp` for sites with third-party embeds.\n- `Permissions-Policy` should enumerate every feature you want to deny, not rely on defaults.\n\nVerify with:\n\n```bash\ncurl -sI https://example.com | grep -iE 'strict-transport|x-content-type|x-frame|referrer-policy|permissions-policy|cross-origin'\n```\n\n---\n\n## Sitemap.xml structure\n\nFor multilingual sites, use a sitemap index referencing per-locale sitemaps.\n\n```xml\n<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<sitemapindex xmlns=\"http://www.sitemaps.org/schemas/sitemap/0.9\">\n  <sitemap><loc>https://example.com/sitemap-en.xml</loc></sitemap>\n  <sitemap><loc>https://example.com/sitemap-fr.xml</loc></sitemap>\n</sitemapindex>\n```\n\nEach per-locale sitemap declares `xhtml:link` alternates with `hreflang`:\n\n```xml\n<url>\n  <loc>https://example.com/en/page</loc>\n  <xhtml:link rel=\"alternate\" hreflang=\"en\" href=\"https://example.com/en/page\"/>\n  <xhtml:link rel=\"alternate\" hreflang=\"fr\" href=\"https://example.com/fr/page\"/>\n  <xhtml:link rel=\"alternate\" hreflang=\"x-default\" href=\"https://example.com/en/page\"/>\n</url>\n```\n\n---\n\n## TONE.md template\n\nPlace at `.agents/TONE.md` or repo root. Fill in based on the user's writing samples and preferences.\n\n```markdown\n# Tone of voice: [Site name]\n\n## Audience\n\n- Primary: [e.g., senior Go developers shipping production systems]\n- Secondary: [e.g., engineering managers evaluating libraries]\n- Reading level: [e.g., technical, no hand-holding]\n- Language: [e.g., English, with some French for FR-specific pages]\n\n## Voice\n\n- Direct, dense, no filler.\n- Contrarian when warranted.\n- Data-grounded: claims need numbers or links.\n- Concrete over abstract: prefer \"200ms p95\" to \"fast\".\n- Assume reader has context, skip primers.\n\n## Forbidden words and patterns\n\n- AI-sounding openers: \"In today's fast-paced world\", \"Let's dive into\", \"It's worth noting that\".\n- Vague adjectives: \"crucial\", \"essential\", \"powerful\", \"robust\", \"comprehensive\", \"seamless\", \"innovative\".\n- Empty verbs: \"delve into\", \"leverage\", \"utilize\", \"facilitate\".\n- Hedging: \"might potentially\", \"may possibly\", \"kind of\", \"sort of\".\n- Em dash character (\"—\") forbidden. Use commas, parentheses, or two sentences.\n- Marketing fluff: \"game-changing\", \"revolutionary\", \"next-generation\", \"world-class\".\n\n## Required patterns\n\n- One concrete example per claim.\n- Numbers when possible. Prefer \"20% faster\" over \"much faster\".\n- Code samples for technical content. Short, runnable, idiomatic.\n\n## Sentence and paragraph rules\n\n- Average sentence length: 12-18 words.\n- Max paragraph length: 4 sentences.\n- One idea per paragraph.\n- Section headers are statements, not questions.\n\n## Good examples (from existing content)\n\n- \"Product XYZ hit $1m ARR without paying for ads. The community wants feature-ABC done right.\"\n- \"Tool XYZ gives 50× benchmark speedups and 5% production gains. Both numbers are true. Only one matters.\"\n\n## Bad examples (to avoid)\n\n- \"Product XYZ is a powerful, comprehensive productivity tool that leverages documentation to seamlessly empower designers.\"\n- \"In today's fast-paced development landscape, choosing the right productivity tool is crucial.\"\n\n## Address form (FR only)\n\n- `tu` vs `vous` must be chosen deliberately and applied consistently site-wide. Mixed forms on the same site are a copywriting error.\n- Default by site type:\n  - `doc-site` (OSS lib, developer tools): **tu** — developer community is informal; \"vous\" feels corporate and creates distance.\n  - `SaaS-app` (B2B, enterprise): **vous** — default to formal unless the product targets solo developers or the brand is explicitly casual.\n  - `marketing/lead-gen` (consumer-facing): **tu** if the audience is young or tech-savvy; **vous** if the audience is professional or older.\n  - `training/paid-course`: **tu** — learning context is personal; \"vous\" creates unnecessary formality.\n  - `personal-portfolio`: **vous** — professional register by default.\n- Ask the user explicitly if the default does not fit: \"Which address form?\" (`tu` | `vous` | `already-specified-in-TONE.md`)\n- Record the chosen form in TONE.md under `Address form: tu | vous` and enforce it in every copy review and humanizer pass.\n\n## Localization notes\n\n- FR content: use guillemets « » not quotes, use non-breaking spaces before `: ; ? !`, avoid anglicisms (\"faire du sens\", \"adresser un problème\").\n- EN content: US spelling.\n```\n\nThe skill should read TONE.md at the start of any copywriting task and pass its constraints to any delegated copywriting skill. After drafting, run the humanizer in the matching language.\n\nFile v1.2.0:references/weekly-seo-agent.md\n\n# Weekly SEO maintenance sub-agent\n\nDefinition for a scheduled background agent — a subagent or custom agent on any harness (see \"Agent definition file\" below for the concrete equivalents), such as Hermes or Claude Cowork Routines — that runs weekly post-launch to monitor SEO health and surface action items.\n\n## Setup\n\n1. Copy the agent definition for your harness (see \"Agent definition file\" below) into the location that harness's block specifies, in the site's repo (or a dedicated ops repo if you manage multiple sites).\n2. Confirm the following MCP servers (or equivalent API access) are connected:\n   - **Ahrefs MCP** (required, for backlinks and rankings)\n   - **PostHog MCP** (required, for traffic correlation)\n   - **Google Search Console** (recommended, via community MCP such as `gsc-mcp`; if no MCP, fall back to `curl` with a service account credential file)\n   - **Web search** (built-in on most harnesses, for SERP feature checks and competitor monitoring)\n3. Confirm the agent has access to the project source code if they apply to the site's content.\n4. Schedule weekly execution. Options:\n   - Cron running that harness's headless/non-interactive invocation (e.g. `claude --dangerously-skip-permissions -p \"/agents weekly-seo\"` on Claude Code, `copilot -p \"/agent weekly-seo\"` on Copilot CLI) — only in a trusted environment\n   - The harness's own scheduled/background-agent feature, where one exists (e.g. Claude Cowork, Hermes)\n   - GitHub Actions weekly schedule, posting the report to a Slack channel\n   - Manual invocation each Monday morning\n\nWhen MCP servers are not available, fall back to a browser extension or headless browser where the harness supports one, or to direct API calls per the \"MCP usage\" section in each harness's block below.\n\n## What the agent does\n\nRun all 10 tasks below in one weekly pass. Each task produces a section of the final report.\n\n### 1. Ranking changes (GSC + Ahrefs)\n\n- Pull top 50 queries by impressions for the last 7 days from Google Search Console.\n- Compare positions, impressions, clicks, and CTR to the prior 7 days.\n- Flag any (page, query) pair that:\n  - Dropped more than 5 positions\n  - Lost more than 20% impressions\n  - Lost more than 30% clicks while position is stable (CTR collapse, often a SERP feature stealing clicks)\n- Output: ordered list of (page, query, delta, hypothesis, recommended action).\n\n### 2. Page-2 opportunities (GSC)\n\n- Identify queries ranking positions 11 through 20 with more than 100 impressions in 7 days.\n- For the top 5: fetch the current page 1 SERP via `web_search` and compare structure, depth, and recency of the top 3 results to the site's current content.\n- Output: content gap analysis with specific edit suggestions (add FAQ section, expand introduction, add benchmark table, etc.).\n\n### 3. New backlinks (Ahrefs MCP)\n\n- Pull new referring domains acquired in the last 7 days.\n- Categorize each: high authority (DR > 50), niche relevant (matches site topic), neutral, spam.\n- Flag spam links for potential disavow file submission.\n- Output: list of new links with category, plus a draft disavow line for any spam.\n\n### 4. Lost backlinks (Ahrefs MCP)\n\n- Pull referring domains lost in the last 7 days.\n- For losses from domains with DR > 40 or known niche relevance: draft outreach email asking why and offering to fix any broken links.\n- Output: list of lost links plus draft outreach for high-value losses.\n\n### 5. Core Web Vitals drift (GSC + PageSpeed Insights)\n\n- Pull the Core Web Vitals report from GSC (mobile and desktop separately).\n- Compare to the prior week.\n- Flag any URL group that crossed from \"Good\" to \"Needs improvement\" or \"Poor\".\n- For each flagged group: run PageSpeed Insights via `web_fetch` on a representative URL and identify the failing metric (LCP, INP, or CLS) and likely cause.\n- Output: list of affected URL patterns with proposed fixes.\n\n### 6. Indexation health (GSC)\n\n- Pull the Page Indexing report.\n- Compare \"Indexed\" and \"Not indexed\" counts week-over-week.\n- For new entries in \"Not indexed\", group by reason (Discovered not indexed, Crawled not indexed, Excluded by noindex, Soft 404, etc.).\n- Output: per-reason summary with recommended fix.\n\n### 7. AI bot traffic (PostHog MCP)\n\n- Query PostHog for sessions where the user agent matches `(GPTBot|ClaudeBot|PerplexityBot|Google-Extended|anthropic-ai|ChatGPT-User|CCBot|Bytespider|Amazonbot)`.\n- Compare counts to the prior week, broken down by bot.\n- If the site type is `doc-site` and counts are growing: positive signal, surface as a metric.\n- If the site type is `marketing/lead-gen` or `paid-course` and any AI bot has nonzero traffic: verify `robots.txt` is actually blocking by fetching `https://example.com/robots.txt` and grepping for the bot. If it should block but isn't, this is a blocker.\n- Output: per-bot weekly count with delta, plus blockers if any bot is reaching pages it should not.\n\n### 8. Competitor SERP monitoring\n\n- For the top 5 target keywords (configured per site in a YAML or JSON file the agent reads): capture the current top 3 SERP results via `web_search`.\n- Compare to the prior week's snapshot (the agent should persist last week's snapshot).\n- Flag new entrants in the top 3 (potential threat) and dropped competitors (potential opportunity).\n- Output: per-keyword SERP delta with strategic note.\n\n### 9. Content freshness audit\n\n- List pages older than 6 months (use Git log on the content files, or GSC \"Last crawled\" date) with declining clicks over the trailing 4 weeks.\n- For the top 5 by lost clicks: recommend a refresh priority based on remaining traffic, topic stability, and competitor SERP activity.\n- Output: refresh queue with effort estimate.\n\n### 10. Schema and structured data validity\n\n- Sample 5 pages at random plus the homepage.\n- For each, extract the JSON-LD via `curl -s URL | grep -A 200 'application/ld+json'`.\n- Validate against schema.org by checking required properties for the declared `@type` (the agent has a local rules file or fetches schema.org definitions).\n- Output: list of breakages with file path and fix.\n\n### 11. Stats memory snapshot\n\nAt the end of every run, append a row to `weekly-seo/memory/stats.csv` (create if missing):\n\n```\ndate,indexed_pages,clicks_7d,impressions_7d,avg_position,new_backlinks,lost_backlinks,lcp_ms,cls,inp_ms,ai_bot_sessions\n```\n\nThis builds a longitudinal record the agent can query in future runs for trend analysis (e.g., 4-week rolling average, detecting regressions that don't show up in week-over-week deltas).\n\nAlso append to `weekly-seo/memory/keywords.csv` (one row per target keyword per run):\n\n```\ndate,keyword,position,impressions,clicks,ctr,page_url\n```\n\nThese two files are the agent's persistent memory. Never truncate or overwrite them. Always append.\n\n### 12. Change log (what worked)\n\nRead `weekly-seo/memory/changelog.md` (create if missing). This file is a running log of **changes applied to the site** and their measured impact.\n\n**On every run:**\n\n1. For each entry in the changelog with `status: pending-validation` and a `measure_after` date that has now passed: pull the relevant metric (rankings, clicks, CWV, etc.) for the affected page or keyword and compare to the baseline recorded at change time. Update the entry with `status: validated` or `status: no-effect`, the measured delta, and a one-sentence conclusion.\n2. At the end of the report, emit a **\"What worked\" section** listing only `validated` entries with positive delta, ordered by impact. This is the institutional memory of SEO wins.\n\n**When instructed to log a change** (user or orchestrator passes a change description):\n\nAppend to `weekly-seo/memory/changelog.md`:\n\n```markdown\n## YYYY-MM-DD — <short title>\n\n- **Page/scope**: `https://example.com/page` (or \"site-wide\")\n- **Change**: one-sentence description of what was done\n- **Hypothesis**: why this should improve the metric\n- **Baseline**: clicks=N, position=N, LCP=Nms (snapshot at time of change)\n- **Metric to watch**: clicks | position | LCP | CLS | INP | backlinks\n- **Measure after**: YYYY-MM-DD (typically 3–4 weeks out)\n- **Status**: pending-validation\n```\n\nNever delete changelog entries. `no-effect` entries are as valuable as wins — they prevent re-testing the same hypothesis.\n\n## Output format\n\nThe agent produces a single Markdown report saved to `weekly-seo/YYYY-MM-DD.md` and (optionally) posted to Slack.\n\nReport structure:\n\n```markdown\n# Weekly SEO Report: example.com (YYYY-MM-DD)\n\n## Summary\n\n- Indexed pages: N (delta vs last week)\n- Total clicks (7d): N (delta)\n- Total impressions (7d): N (delta)\n- New backlinks: N | Lost: N\n- AI bot sessions: N (delta)\n\n## 🔴 Blockers\n\n[ordered list of items requiring action this week]\n\n## 🟡 Should fix\n\n[ordered list of items worth addressing next sprint]\n\n## 🟢 Opportunities\n\n[ordered list of growth opportunities, e.g., page-2 keywords, competitor weakness]\n\n## 📊 Per-task details\n\n### 1. Ranking changes\n\n### 2. Page-2 opportunities\n\n### 3. New backlinks\n\n### 4. Lost backlinks\n\n### 5. Core Web Vitals drift\n\n### 6. Indexation health\n\n### 7. AI bot traffic\n\n### 8. Competitor SERP monitoring\n\n### 9. Content freshness\n\n### 10. Schema validity\n```\n\n## Agent definition file\n\nSame 12 tasks, same `weekly-seo/config.yml`, same memory files, same fallback behavior on every harness below — only the agent-definition schema and file path change. Pick the block matching your harness; none of them is the \"real\" one. This skill is not exhaustive on harness internals; verify field names against each harness's current docs before relying on them in production.\n\n<details>\n<summary>Google Antigravity — place at <code>.agents/agents/weekly-seo.md</code></summary>\n\n[View agent definition](../assets/weekly-seo-antigravity.md)\n\n</details>\n\n<details>\n<summary>Claude Code — place at <code>.claude/agents/weekly-seo.md</code></summary>\n\n[View agent definition](../assets/weekly-seo-claude-code.md)\n\n</details>\n\n<details>\n<summary>Gemini CLI — place at <code>.gemini/agents/weekly-seo.md</code></summary>\n\n[View agent definition](../assets/weekly-seo-gemini-cli.md)\n\n</details>\n\n<details>\n<summary>OpenCode — place at <code>.opencode/agent/weekly-seo.md</code></summary>\n\n[View agent definition](../assets/weekly-seo-opencode.md)\n\n</details>\n\n<details>\n<summary>GitHub Copilot CLI — place at <code>.github/agents/weekly-seo.agent.md</code></summary>\n\n[View agent definition](../assets/weekly-seo-copilot-cli.md) — Copilot CLI has no built-in scheduler: invoke it interactively with `/agent weekly-seo`, or trigger it headlessly every Monday via an external cron job running `copilot -p \"/agent weekly-seo\"`.\n\n</details>\n\n<details>\n<summary>Mistral Vibe — place config at <code>.vibe/agents/weekly-seo.toml</code> and prompt at <code>.vibe/prompts/weekly-seo.md</code></summary>\n\n[View config](../assets/weekly-seo-vibe.toml) · [View prompt](../assets/weekly-seo-vibe-prompt.md)\n\nReads and web access run unattended (`permission = \"always\"`); writing files and running shell commands ask for confirmation each time (`permission = \"ask\"`), since those are the two actions this agent could get wrong destructively. If you want fully unattended weekly runs (e.g. scheduled via cron, matching the Claude Code \"Cron\" option in Setup), raise `write_file` and `run_shell_command` to `\"always\"` yourself — that's a deliberate trust decision for the operator to make, not a default this doc should set.\n\n</details>\n\nWindsurf, Cursor, and Codex CLI don't have a confirmed, documented custom scheduled-agent-file schema at the time of writing — for those, take the same structure shown above (name, description, tool list, system prompt covering Configuration/Tasks/MCP usage/Output/Tone) and adapt it to whatever custom agent or automation mechanism the harness exposes, then verify against its current docs.\n\n## Config file template\n\nPlace at `weekly-seo/config.yml` in the site's repo.\n\n```yaml\ndomain: example.com\ngsc_property: sc-domain:example.com\nahrefs_project_id: 12345\nposthog_project_id: 67890\nslack_webhook: https://hooks.slack.com/services/...\ntarget_keywords:\n  - \"keyword one\"\n  - \"keyword two\"\n  - \"keyword three\"\n  - \"keyword four\"\n  - \"keyword five\"\nsite_type: doc-site # or marketing, saas-app, paid-course, portfolio\n```\n\nThe agent reads this config to scope every task. If the file is missing, the agent asks the user if invoked interactively, or fails with a clear error if invoked headlessly.\n\nFile v1.2.0:assets/weekly-seo-antigravity.md\n\n---\nname: weekly-seo\ndescription: Weekly SEO maintenance and monitoring for a launched site. Run every Monday. Pulls data from Google Search Console, Ahrefs, PostHog, and web search to monitor rankings, backlinks, Core Web Vitals, indexation, AI bot traffic, competitor SERPs, content freshness, and schema validity. Produces a Markdown report with blockers, should-fix items, and opportunities.\ntools:\n  - view_file\n  - write_file\n  - grep_search\n  - run_command\n  - web_search\n  - read_url\nsubagent: true\nmainAgent: false\nmodel: pro\ncommandExecutionPolicy: sandbox\n---\n\n# System Prompt\n\nYou are a weekly SEO maintenance agent for a single launched site. Your job is to run 12 health-check tasks every Monday and produce a structured Markdown report.\n\n## Configuration\n\nRead `weekly-seo/config.yml` for site-specific config: domain, target keywords (top 5), GSC property ID, Ahrefs project ID, PostHog project ID, Slack webhook URL (optional).\n\n## Tasks\n\n[Run all 12 tasks defined in references/weekly-seo-agent.md of the site-launch-checklist skill. For each task, follow the detailed instructions there.]\n\nTasks 11 and 12 are mandatory on every run:\n\n- **Task 11 (stats memory)**: append to `weekly-seo/memory/stats.csv` and `weekly-seo/memory/keywords.csv`. Never skip.\n- **Task 12 (changelog validation)**: check `weekly-seo/memory/changelog.md` for `pending-validation` entries whose `measure_after` date has passed; update their status; emit the \"What worked\" section in the report.\n\n## MCP usage\n\nConfigure Ahrefs, PostHog, and Google Search Console as MCP servers in Antigravity's settings (project or global). Once configured, they are used as follows:\n\n- Ahrefs MCP: tasks 1, 3, 4\n- PostHog MCP: task 7\n- Google Search Console MCP: tasks 1, 2, 5, 6\n- `web_search` / `read_url`: tasks 2, 8\n\nIf an MCP server is unavailable, fall back to `run_command` with `curl` against the equivalent API, using credentials stored in `.env` (do not commit). Surface any data-source unavailability in the report header so the user knows the run was partial.\n\n## Output\n\nWrite the report to `weekly-seo/YYYY-MM-DD.md` using `write_file`. If a Slack webhook is configured, post the Summary + Blockers sections to Slack via `run_command` (curl).\n\n## Tone\n\nTerse, action-oriented. Each blocker is one sentence stating the problem and one sentence stating the fix. No filler.\n\nFile v1.2.0:assets/weekly-seo-claude-code.md\n\n---\nname: weekly-seo\ndescription: Weekly SEO maintenance and monitoring for a launched site. Run every Monday. Pulls data from Google Search Console, Ahrefs, PostHog, and web search to monitor rankings, backlinks, Core Web Vitals, indexation, AI bot traffic, competitor SERPs, content freshness, and schema validity. Produces a Markdown report with blockers, should-fix items, and opportunities.\ntools: WebFetch, WebSearch, Bash, Read, Write\n---\n\nYou are a weekly SEO maintenance agent for a single launched site. Your job is to run 12 health-check tasks every Monday and produce a structured Markdown report.\n\n## Configuration\n\nRead `weekly-seo/config.yml` for site-specific config: domain, target keywords (top 5), GSC property ID, Ahrefs project ID, PostHog project ID, Slack webhook URL (optional).\n\n## Tasks\n\n[Run all 12 tasks defined in references/weekly-seo-agent.md of the site-launch-checklist skill. For each task, follow the detailed instructions there.]\n\nTasks 11 and 12 are mandatory on every run:\n\n- **Task 11 (stats memory)**: append to `weekly-seo/memory/stats.csv` and `weekly-seo/memory/keywords.csv`. Never skip.\n- **Task 12 (changelog validation)**: check `weekly-seo/memory/changelog.md` for `pending-validation` entries whose `measure_after` date has passed; update their status; emit the \"What worked\" section in the report.\n\n## MCP usage\n\n- Ahrefs MCP: tasks 1, 3, 4\n- PostHog MCP: task 7\n- Google Search Console (via community MCP or curl): tasks 1, 2, 5, 6\n- Web search (built-in): tasks 2, 8\n\nIf an MCP is unavailable, fall back to Claude for Chrome, to a web browser, to the equivalent API call via `curl` or `web_fetch` with credentials stored in `.env` (do not commit). Surface any data-source unavailability in the report header so the user knows the run was partial.\n\n## Output\n\nWrite the report to `weekly-seo/YYYY-MM-DD.md`. If a Slack webhook is configured, post the Summary + Blockers sections to Slack.\n\n## Tone\n\nTerse, action-oriented. Each blocker is one sentence stating the problem and one sentence stating the fix. No filler.\n\nFile v1.2.0:assets/weekly-seo-copilot-cli.md\n\n---\nname: weekly-seo\ndescription: \"Weekly SEO maintenance and monitoring for a launched site. Run every Monday. Pulls data from Google Search Console, Ahrefs, PostHog, and web search to monitor rankings, backlinks, Core Web Vitals, indexation, AI bot traffic, competitor SERPs, content freshness, and schema validity. Produces a Markdown report with blockers, should-fix items, and opportunities.\"\ntools: [\"search\", \"codebase\", \"editFiles\", \"runCommands\"]\n---\n\nYou are a weekly SEO maintenance agent for a single launched site. Your job is to run 12 health-check tasks every Monday and produce a structured Markdown report.\n\n## Configuration\n\nRead `weekly-seo/config.yml` for site-specific config: domain, target keywords (top 5), GSC property ID, Ahrefs project ID, PostHog project ID, Slack webhook URL (optional).\n\n## Tasks\n\n[Run all 12 tasks defined in references/weekly-seo-agent.md of the site-launch-checklist skill. For each task, follow the detailed instructions there.]\n\nTasks 11 and 12 are mandatory on every run:\n\n- **Task 11 (stats memory)**: append to `weekly-seo/memory/stats.csv` and `weekly-seo/memory/keywords.csv`. Never skip.\n- **Task 12 (changelog validation)**: check `weekly-seo/memory/changelog.md` for `pending-validation` entries whose `measure_after` date has passed; update their status; emit the \"What worked\" section in the report.\n\n## MCP usage\n\nConfigure Ahrefs, PostHog, and Google Search Console as MCP servers in Copilot CLI's MCP config (`mcp-server` settings), then use them for:\n\n- Ahrefs MCP: tasks 1, 3, 4\n- PostHog MCP: task 7\n- Google Search Console MCP: tasks 1, 2, 5, 6\n- Web search (`search` tool): tasks 2, 8\n\nIf an MCP server is unavailable, fall back to a web browser, or to the equivalent API call via `runCommands` (`curl`) with credentials stored in `.env` (do not commit). Surface any data-source unavailability in the report header so the user knows the run was partial.\n\n## Output\n\nWrite the report to `weekly-seo/YYYY-MM-DD.md`. If a Slack webhook is configured, post the Summary + Blockers sections to Slack via `curl`.\n\n## Tone\n\nTerse, action-oriented. Each blocker is one sentence stating the problem and one sentence stating the fix. No filler.\n\n## Scheduling\n\nCopilot CLI has no built-in scheduler: invoke this agent interactively with `/agent weekly-seo`, or trigger it headlessly every Monday via an external cron job running `copilot -p \"/agent weekly-seo\"`.\n\nFile v1.2.0:assets/weekly-seo-gemini-cli.md\n\n---\nname: weekly-seo\ndescription: Weekly SEO maintenance and monitoring for a launched site. Run every Monday. Pulls data from Google Search Console, Ahrefs, PostHog, and web search to monitor rankings, backlinks, Core Web Vitals, indexation, AI bot traffic, competitor SERPs, content freshness, and schema validity. Produces a Markdown report with blockers, should-fix items, and opportunities.\nkind: local\ntools:\n  - read_file\n  - write_file\n  - run_shell_command\n  - web_fetch\n  - google_web_search\nmodel: inherit\ntemperature: 0.2\nmax_turns: 20\n---\n\nYou are a weekly SEO maintenance agent for a single launched site. Your job is to run 12 health-check tasks every Monday and produce a structured Markdown report.\n\n## Configuration\n\nRead `weekly-seo/config.yml` for site-specific config: domain, target keywords (top 5), GSC property ID, Ahrefs project ID, PostHog project ID, Slack webhook URL (optional).\n\n## Tasks\n\n[Run all 12 tasks defined in references/weekly-seo-agent.md of the site-launch-checklist skill. For each task, follow the detailed instructions there.]\n\nTasks 11 and 12 are mandatory on every run:\n\n- **Task 11 (stats memory)**: append to `weekly-seo/memory/stats.csv` and `weekly-seo/memory/keywords.csv`. Never skip.\n- **Task 12 (changelog validation)**: check `weekly-seo/memory/changelog.md` for `pending-validation` entries whose `measure_after` date has passed; update their status; emit the \"What worked\" section in the report.\n\n## MCP usage\n\n- Ahrefs MCP: tasks 1, 3, 4\n- PostHog MCP: task 7\n- Google Search Console (via community MCP or curl): tasks 1, 2, 5, 6\n- Web search (`google_web_search`): tasks 2, 8\n\nAhrefs, PostHog, and GSC MCP servers can be declared inline in this subagent's frontmatter under an `mcpServers` block, or configured globally for the Gemini CLI session — either way, this agent picks them up automatically when present.\n\nIf an MCP is unavailable, fall back to a web browser, or to the equivalent API call via `run_shell_command` (`curl`) or `web_fetch` with credentials stored in `.env` (do not commit). Surface any data-source unavailability in the report header so the user knows the run was partial.\n\n## Output\n\nWrite the report to `weekly-seo/YYYY-MM-DD.md`. If a Slack webhook is configured, post the Summary + Blockers sections to Slack.\n\n## Tone\n\nTerse, action-oriented. Each blocker is one sentence stating the problem and one sentence stating the fix. No filler.\n\nFile v1.2.0:assets/weekly-seo-opencode.md\n\n---\ndescription: Weekly SEO maintenance and monitoring for a launched site. Run every Monday. Pulls data from Google Search Console, Ahrefs, PostHog, and web search to monitor rankings, backlinks, Core Web Vitals, indexation, AI bot traffic, competitor SERPs, content freshness, and schema validity. Produces a Markdown report with blockers, should-fix items, and opportunities.\nmode: subagent\ntools:\n  read: true\n  write: true\n  bash: true\n  webfetch: true\npermission:\n  bash: \"allow\"\n---\n\nYou are a weekly SEO maintenance agent for a single launched site. Your job is to run 12 health-check tasks every Monday and produce a structured Markdown report.\n\n## Configuration\n\nRead `weekly-seo/config.yml` for site-specific config: domain, target keywords (top 5), GSC property ID, Ahrefs project ID, PostHog project ID, Slack webhook URL (optional).\n\n## Tasks\n\n[Run all 12 tasks defined in references/weekly-seo-agent.md of the site-launch-checklist skill. For each task, follow the detailed instructions there.]\n\nTasks 11 and 12 are mandatory on every run:\n\n- **Task 11 (stats memory)**: append to `weekly-seo/memory/stats.csv` and `weekly-seo/memory/keywords.csv`. Never skip.\n- **Task 12 (changelog validation)**: check `weekly-seo/memory/changelog.md` for `pending-validation` entries whose `measure_after` date has passed; update their status; emit the \"What worked\" section in the report.\n\n## MCP usage\n\nConfigure Ahrefs, PostHog, and Google Search Console as MCP servers in OpenCode's configuration (project or global `opencode.json`), then map them to tasks as follows:\n\n- Ahrefs MCP: tasks 1, 3, 4\n- PostHog MCP: task 7\n- Google Search Console MCP (or `bash` + `curl`): tasks 1, 2, 5, 6\n- Web search (via `webfetch` or a configured search MCP): tasks 2, 8\n\nIf an MCP is unavailable, fall back to a web browser, or to the equivalent API call via `bash`/`curl` or `webfetch` with credentials stored in `.env` (do not commit). Surface any data-source unavailability in the report header so the user knows the run was partial.\n\n## Output\n\nWrite the report to `weekly-seo/YYYY-MM-DD.md`. If a Slack webhook is configured, post the Summary + Blockers sections to Slack.\n\n## Tone\n\nTerse, action-oriented. Each blocker is one sentence stating the problem and one sentence stating the fix. No filler.\n\nFile v1.2.0:assets/weekly-seo-vibe-prompt.md\n\nYou are a weekly SEO maintenance agent for a single launched site. Your job is to run 12 health-check tasks every Monday and produce a structured Markdown report.\n\n## Configuration\n\nRead `weekly-seo/config.yml` for site-specific config: domain, target keywords (top 5), GSC property ID, Ahrefs project ID, PostHog project ID, Slack webhook URL (optional).\n\n## Tasks\n\n[Run all 12 tasks defined in references/weekly-seo-agent.md of the site-launch-checklist skill. For each task, follow the detailed instructions there.]\n\nTasks 11 and 12 are mandatory on every run:\n\n- **Task 11 (stats memory)**: append to `weekly-seo/memory/stats.csv` and `weekly-seo/memory/keywords.csv`. Never skip.\n- **Task 12 (changelog validation)**: check `weekly-seo/memory/changelog.md` for `pending-validation` entries whose `measure_after` date has passed; update their status; emit the \"What worked\" section in the report.\n\n## MCP usage\n\nConfigure Ahrefs, PostHog, and Google Search Console as MCP servers in Vibe's project or global configuration:\n\n- Ahrefs MCP: tasks 1, 3, 4\n- PostHog MCP: task 7\n- Google Search Console MCP (or `run_shell_command` calling `curl`): tasks 1, 2, 5, 6\n- `web_search`: tasks 2, 8\n\nIf an MCP is unavailable, fall back to a web browser, or to the equivalent API call via `run_shell_command` (`curl`) or `web_fetch` with credentials stored in `.env` (do not commit). Surface any data-source unavailability in the report header so the user knows the run was partial.\n\n## Output\n\nWrite the report to `weekly-seo/YYYY-MM-DD.md`. If a Slack webhook is configured, post the Summary + Blockers sections to Slack.\n\n## Tone\n\nTerse, action-oriented. Each blocker is one sentence stating the problem and one sentence stating the fix. No filler.\n\nFile v1.2.0:skill-card.md\n\n## Description:\n\nPre-launch checklist for shipping a new website. Orchestrates analytics setup (GA4, PostHog, Google Search Console, Ahrefs), legal compliance, security headers and audit, SEO and GEO with keyword research validated against Google Trends (robots.txt, sitemaps, llms.txt, AI policy, schema markup, hreflang), copywriting consistency via a TONE.md and a humanizer pass in the matching language, OpenGraph and social previews, full favicon set with manifest, quality gates (Lighthouse, Core Web Vitals, WCAG accessibility, mobile testing), and setup of a weekly SEO agent.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[samber](https://clawhub.ai/user/samber)\n\n### License/Terms of Use:\n\nMIT\n\n## Use Case:\n\nDevelopers, site owners, and launch teams use this skill to run an interactive pre-launch audit for websites, apps, documentation sites, SaaS pages, paid courses, and portfolios. It helps verify infrastructure, analytics, legal/compliance posture, security headers, SEO/GEO readiness, social previews, favicons, quality gates, ecosystem links, and weekly SEO maintenance setup.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can lead an agent to install third-party skills or tools that are not pinned to immutable versions.\n\nMitigation: Require explicit user confirmation before each install and review or pin remote packages, skills, commits, and tools before use.\n\nRisk: The weekly SEO maintenance agent may run on a recurring or headless schedule.\n\nMitigation: Run scheduled jobs only in a tightly sandboxed account with read-only credentials where possible and explicit approvals for shell commands, file writes, and outbound posting.\n\nRisk: API credentials and Slack webhooks may be used for analytics, SEO, and reporting workflows.\n\nMitigation: Store credentials in a secrets manager or uncommitted environment configuration, limit credential scope, and review outbound reports before posting to external channels.\n\nRisk: Security evidence marks the release suspicious because it combines remote installs, credential-backed calls, recurring agents, and outbound data flows.\n\nMitigation: Install only after reviewing the release, scan results, requested tools, and data-flow implications for the target workspace.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/samber/skills/site-launch-checklist)\n- [Publisher profile](https://clawhub.ai/user/samber)\n- [Source homepage](https://github.com/samber/cc-skills)\n- [Decisions and matrices](references/decisions.md)\n- [Templates](references/templates.md)\n- [Weekly SEO maintenance sub-agent](references/weekly-seo-agent.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown status reports, checklist guidance, inline shell commands, configuration snippets, and optional agent definition files.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces phase-by-phase launch status with blockers, recommended fixes, optional improvements, and optional weekly SEO report files.]\n\n## Skill Version(s):\n\n1.2.0 (source: frontmatter and server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.1.0: 7 files, 31510 bytes\n\nFiles: evals/evals.json (14175b), references/decisions.md (4022b), references/templates.md (10908b), references/weekly-seo-agent.md (11501b), skill-card.md (3028b), SKILL.md (30954b), _meta.json (140b)\n\nFile v1.1.0:SKILL.md\n\n---\nname: site-launch-checklist\ndescription: Pre-launch checklist for shipping a new website. Orchestrates analytics setup (GA4, PostHog, Google Search Console, Ahrefs), legal compliance, security headers and audit, SEO and GEO with keyword research validated against Google Trends (robots.txt, sitemaps, llms.txt, AI policy, schema markup, hreflang), copywriting consistency via a TONE.md and a humanizer pass in the matching language, OpenGraph and social previews, full favicon set with manifest, quality gates (Lighthouse, Core Web Vitals, WCAG accessibility, mobile testing), and setup of a weekly SEO agent. Use this skill whenever the user mentions launching a site/app, deploying a domain to production, pre-launch audit, shipping a marketing/docs/SaaS site or lead magnet, or says \"checklist for the site\", \"ready to ship\", \"before I go live\", \"audit before launch\", \"ready for prod\", or asks for a site review.\nlicense: MIT\ncompatibility: Requires Claude Code\nuser-invocable: true\nmetadata:\n  author: samber\n  version: \"1.1.0\"\n  openclaw:\n    emoji: \"📊\"\n    homepage: https://github.com/samber/cc-skills\n    install:\n      - kind: npm\n        package: skills\n        bins: [skills]\n      - kind: brew\n        formula: jq\n        bins: [jq]\n    requires:\n      bins:\n        - curl\n        - npm\n        - npx\n        - jq\nallowed-tools: Read Edit Write Glob Grep Agent AskUserQuestion\n---\n\n# Site Launch Checklist\n\nPre-launch audit and setup workflow for shipping a new website. Opinionated for Cloudflare DNS + Vercel hosting + PostHog + Legal context.\n\n## Interaction style (READ FIRST)\n\nThis skill is intentionally interactive. **Use `ask_user_input_v0` aggressively** instead of assuming. Ask one question at a time with 2-4 tappable options. The user will tap, not type.\n\n**Always ask these questions at the start of a run** (one at a time, in this order):\n\n1. Site type: `doc-site` | `marketing/lead-gen` | `SaaS-app` | `training/paid-course` | `personal-portfolio`\n2. Migration: `greenfield-new-domain` | `migration-need-301-redirects` | `replacing-existing-on-same-domain`\n3. Multilingual: `single-locale` | `en` | `fr+en` | `other-multi`\n4. PostHog setup: `hogpost.samber.dev` | `set-up-new-proxy` | `skip-PostHog`\n5. AI scraper policy: `use-default-for-site-type` | `customize-per-bot` | `block-all`\n6. Browser tool available: `claude-chrome-extension` | `playwright` | `neither-skip-browser-checks`\n\n**Ask again at every decision point throughout the phases**, including:\n\n- Whether to install Sentry / BetterStack / Crisp (depends on site type, ask explicitly)\n- www vs apex canonical preference (most sites: apex; ask anyway)\n- Which AI bots to allow if user chose `customize-per-bot`\n- CSP tightness level: `strict-default-src-none` | `balanced-allow-self` | `permissive-for-marketing`\n- Whether to skip a phase entirely (e.g., skip Phase 3 if non-FR site)\n\nNever proceed past a decision point without explicit user input. Verbose checklists without checkpoints are not the goal.\n\n**Never install any MCP server or skill without explicit user confirmation.** Always ask via `ask_user_input_v0` before running `npx skills add`, `claude mcp add`, or any equivalent install command — even when the skill selection workflow proposes a curated subset.\n\n## How to use this skill\n\n1. Run the start-of-session questions above.\n2. Walk the user through phases 1-10 in order. For each phase: a. List items, ask if any should be skipped. b. For each remaining item, run the verification command (see \"Verification tools\" below). c. Report pass/fail. On fail, ask the user if they want to fix now or queue for later.\n3. End with a status report grouped by phase, with blockers, recommended fixes, and optional improvements clearly separated.\n\n## Companion skills\n\nSix skill packs are useful for site launches. **Never install full multi-skill packs**. The actual subset to install is decided at invocation time based on the site type the user confirms.\n\n### Pack inventory\n\n| Pack | What it covers | Typically useful for |\n| --- | --- | --- |\n| `AgriciDaniel/claude-seo` | SEO + GEO + schema + hreflang + sitemaps audits, parallel sub-agents | All site types |\n| `addyosmani/web-quality-skills` | Lighthouse, Core Web Vitals, accessibility, performance, best practices | All site types |\n| `trailofbits/skills` | Security audit (OWASP, headers, dependencies) | All site types |\n| `aaron-he-zhu/seo-geo-claude-skills` | 20 SEO+GEO skills, CORE-EEAT + CITE frameworks, `/seo:` slash commands | Content-heavy sites, competitive niches |\n| `coreyhaines31/marketingskills` | ~30 marketing skills (CRO, copywriting, ads, popups, email, paywalls, etc.) | `marketing/lead-gen`, `SaaS-app`, `training/paid-course` |\n| `jonathimer/devmarketing-skills` | 33 developer-marketing skills (persona, docs-as-marketing, technical tutorials, etc.) | `doc-site`, `SaaS-app` for developers |\n\n### Skill selection workflow (run at session start)\n\nAfter the user confirms site type, for **each pack relevant to that site type**:\n\n1. **List available sub-skills**: `npx skills add owner/repo --list`\n2. **Propose a curated subset** based on site type and the phases this skill will execute. Match each phase's needs to specific sub-skills the listing returns.\n3. **Confirm with the user** via `ask_user_input_v0`. Use multi-select when the proposed list has more than 3 items, single-select (`install-as-proposed` | `let-me-modify` | `skip-this-pack`) otherwise.\n4. **Bulk install the agreed subset**: `npx skills add owner/repo --skill A B C`\n\nRules:\n\n- Sub-skill names live in the pack, not in this SKILL.md. Always query `--list` for the current state. Pack contents change.\n- Never run `npx skills add owner/repo` without `--skill` (that installs everything).\n- Site type → packs mapping (which packs to enumerate, sub-skills still selected per workflow):\n  - `doc-site`: claude-seo, web-quality-skills, trailofbits, seo-geo-claude-skills, devmarketing-skills\n  - `marketing/lead-gen`: claude-seo, web-quality-skills, trailofbits, seo-geo-claude-skills, marketingskills\n  - `SaaS-app`: all six\n  - `training/paid-course`: claude-seo, web-quality-skills, trailofbits, marketingskills\n  - `personal-portfolio`: claude-seo, web-quality-skills, trailofbits, seo-geo-claude-skills (lightweight subset)\n- If the user later requests a phase that needs a sub-skill not yet installed, run the workflow again for that single sub-skill rather than re-installing the whole subset.\n\nThis avoids importing 80+ skills the user does not need, avoids going stale on sub-skill names, and avoids overfitting to a single pack version.\n\nWhen delegating during a phase, do not duplicate work this skill orchestrates. Call the specialist with a narrow scope (e.g., \"run only the security headers sub-audit on URL X\").\n\n## Copywriting voice and humanizer pass\n\nEvery site has visible marketing copy (hero, features, CTAs, meta descriptions, OG descriptions, blog posts, 404 page text). Two layers of polish are mandatory before launch:\n\n### 1. Define `TONE.md` once per site\n\nAsk the user (`ask_user_input_v0`): \"Does this site already have a `TONE.md`?\" (`yes-already-exists` | `no-create-from-template` | `skip-use-default`).\n\nIf creating: write it to `.agents/TONE.md` or repo root `TONE.md`. See `references/templates.md` (section \"TONE.md template\") for the structure.\n\nTONE.md specifies: voice (terse, contrarian, etc.), forbidden patterns (e.g., \"delve\", \"crucial\", em dashes, AI-sounding openers), sentence length preference, audience reading level, examples of good and bad sentences from the user's own writing.\n\n### 2. Run a humanizer pass in the matching language\n\nAfter every drafting step (whether by a copywriting skill, by hand, or by Claude directly), run a humanizer to strip AI patterns.\n\nAsk the user (`ask_user_input_v0`) for the site's primary audience language at the start of the session if not already known:\n\n- `english-global` → `npx skills add https://github.com/blader/humanizer --skill humanizer`\n- `french` → use `samber/humaniseur-fr` (custom French humanizer) or equivalent French-tuned skill\n- `other` → install matching humanizer if available; otherwise the skill writes a short language-specific anti-pattern checklist inline\n\nApply the humanizer to: hero copy, feature descriptions, CTA buttons, meta descriptions, OG/Twitter card descriptions, blog posts, email signup confirmations, 404 page text. Skip for legal pages (mentions légales, CGV) since they have rigid wording requirements.\n\n### 3. Always reference TONE.md when invoking copywriting skills\n\nWhen delegating to any copywriting or content-writing sub-skill (selected at invocation per the skill selection workflow), include `TONE.md` in the prompt context. Pass voice constraints explicitly: \"Follow `.agents/TONE.md`. Avoid the listed patterns. Apply the humanizer after drafting.\"\n\n## Browser interaction preference\n\nMany checks require a real browser (Lighthouse runs, securityheaders.com scan, opengraph.xyz validation, Twitter card validator, mobile viewport, screen reader smoke, Network tab inspection).\n\n**Always prefer the Claude Chrome extension.** Fall back to Playwright only if the Chrome extension is unavailable. If neither is available, ask the user (`ask_user_input_v0`) whether to skip browser checks entirely or wait until they enable one.\n\n## Verification tools\n\nMost checks are doable from the command line without third-party services. Use these tools inline at every phase. Don't trust panels in Cloudflare/Vercel/Google dashboards alone, verify with curl.\n\n**DNS (Phase 1):**\n\n```bash\ndig +short A example.com                          # A record\ndig +short AAAA example.com                       # AAAA (IPv6)\ndig +short MX example.com                         # MX (mail)\ndig +short TXT example.com                        # SPF + verification TXT\ndig +short TXT _dmarc.example.com                 # DMARC\ndig +short TXT default._domainkey.example.com     # DKIM (selector varies)\ndig +short CAA example.com                        # CAA\ndig +dnssec example.com | grep RRSIG              # DNSSEC active\n```\n\n**TLS / HTTPS (Phase 1):**\n\n```bash\ncurl -sIL https://example.com | head             # follow redirects\ncurl -sI https://www.example.com                 # check www handling\nopenssl s_client -showcerts -connect example.com:443 < /dev/null 2>/dev/null | openssl x509 -noout -dates\n```\n\n**Headers (Phase 4):**\n\n```bash\ncurl -sI https://example.com | grep -iE 'content-security-policy|strict-transport-security|x-frame-options|x-content-type-options|referrer-policy|permissions-policy'\n# Full header dump:\ncurl -sI https://example.com\n# External graders:\ncurl -s \"https://api.securityheaders.com/?q=https://example.com&followRedirects=on&hide=on\" -I | grep -i 'x-grade'\n```\n\n**SEO files (Phase 5):**\n\n```bash\ncurl -s https://example.com/robots.txt\ncurl -sI https://example.com/sitemap.xml\ncurl -s https://example.com/sitemap.xml | head -40\ncurl -s https://example.com/llms.txt\n# Schema (JSON-LD):\ncurl -s https://example.com/ | grep -A 50 'application/ld+json'\n# hreflang:\ncurl -s https://example.com/ | grep -i hreflang\n```\n\n**Open Graph & social (Phase 6):**\n\n```bash\ncurl -s https://example.com/page | grep -iE 'og:|twitter:|<title|name=\"description\"'\n```\n\n**Favicons & manifest (Phase 7):**\n\n```bash\ncurl -sI https://example.com/favicon.ico\ncurl -sI https://example.com/favicon.svg\ncurl -sI https://example.com/apple-touch-icon.png\ncurl -s https://example.com/manifest.json | jq .\n```\n\n**404 / 500 / redirects:**\n\n```bash\ncurl -sI https://example.com/this-does-not-exist\ncurl -sIL https://example.com/old-url     # verify 301 chain\n```\n\nAlways run the relevant command, paste the output to the user when reporting, then ask (via `ask_user_input_v0`) whether to fix immediately or queue.\n\n---\n\n## Phase 1: Domain & Infrastructure\n\nMost of this is one-click via Cloudflare's dashboard if the domain is on Cloudflare.\n\nAsk first: \"Is the domain already on Cloudflare with the standard config from previous launches?\" (`yes-standard` | `yes-needs-review` | `no-fresh-setup`)\n\nChecklist:\n\n- [ ] Cloudflare: proxy ON for apex + www, TLS 1.3 minimum, \"Always Use HTTPS\" enabled, HSTS preload enabled in Cloudflare SSL/TLS settings\n- [ ] DNS A/AAAA or CNAME pointing to Vercel (verify with `dig +short A example.com`)\n- [ ] MX records for Google Workspace (verify with `dig +short MX example.com`)\n- [ ] SPF, DKIM, DMARC records (verify all 3 with the dig commands above)\n- [ ] CAA records restricting cert issuance (verify with `dig +short CAA example.com`)\n- [ ] DNSSEC enabled at registrar level (verify with `dig +dnssec`)\n- [ ] Vercel: project linked to repo, prod + preview env vars set, custom domain attached, prod and preview aliases correct\n- [ ] Decide www vs apex canonical, configure 308 redirect for the non-canonical (verify with `curl -sIL https://www.example.com`)\n- [ ] Custom 404 page renders (verify with `curl -sI https://example.com/does-not-exist`)\n- [ ] Custom 500 page exists (cannot easily verify without forcing an error, ask user)\n- [ ] If migration: 301 redirect map for every old URL (loop verification with `curl -sIL` per URL)\n\n### Backups\n\nIf you don't configure backups at launch, you never will. Do it now.\n\nAsk the user (`ask_user_input_v0`): \"Which data stores does this app write to?\" (`database-only` | `database-plus-file-storage` | `file-storage-only` | `stateless-no-persistent-data`). If `stateless-no-persistent-data`, skip this section.\n\n**Database:**\n\n- [ ] Automated daily backups enabled at the provider level (Neon, Supabase, PlanetScale, Railway, RDS — each has a one-click toggle). Verify by opening the backup panel and confirming the last backup timestamp is recent.\n- [ ] Retention policy set to ≥30 days\n- [ ] Point-in-time recovery (PITR) enabled if available (Neon, Supabase, RDS all support it)\n- [ ] Off-site copy: if the provider stores backups in the same region as the primary, configure cross-region replication or a nightly export to a separate storage account (S3, R2, GCS)\n- [ ] **Restore drill performed before launch**: pick a recent backup, restore to a staging database, verify row counts and a sample query. A backup you haven't tested is not a backup.\n\n**File storage (if applicable — S3, R2, GCS, Cloudflare Images):**\n\n- [ ] Versioning enabled on the primary bucket\n- [ ] Cross-region replication or a scheduled sync to a secondary bucket. Backblaze B2 is a cheap, reliable option for off-site copies (significantly cheaper than S3/GCS egress). Use `rclone` to sync from S3/R2/GCS → B2 on a daily cron.\n- [ ] Lifecycle rule: transition old versions to cheaper storage after 30 days, delete after 90 days (adjust to cost tolerance)\n\n**Secrets / environment variables:**\n\n- [ ] All env vars documented and stored in a secrets manager (1Password, Doppler, Vault, or equivalent). Not in a `.env` file on someone's laptop.\n- [ ] Verify: if every engineer's machine burned tonight, could a new team member restore prod from scratch using only the secrets manager + git?\n\n**Monitoring:**\n\n- [ ] Set up an alert (email or Slack) if the daily backup job fails. Most providers support this natively; configure it before closing the backup panel.\n\n---\n\n## Phase 2: Analytics & Observability\n\nMost third-party integrations are one-click via Cloudflare or Vercel.\n\n**For the conditional tools (Crisp, Sentry, BetterStack), use `ask_user_input_v0`** to confirm per site type. See `references/decisions.md` for the observability tier matrix.\n\n**Always-on:**\n\n- [ ] Google Analytics 4: property created, measurement ID embedded, gated behind CNIL consent\n- [ ] PostHog: based on user's earlier answer:\n  - If `hogpost.samber.dev`: configure client with `api_host: \"https://hogpost.samber.dev\"` and verify CORS allows the new domain (test with browser console or `curl -H \"Origin: https://newsite.com\" -I https://hogpost.samber.dev/decide`)\n  - If `set-up-new-proxy`: add path rewrite in `next.config.js` to `us.i.posthog.com` and `us-assets.i.posthog.com`, init client with `api_host: \"/ingest\"`\n  - If `skip-PostHog`: skip\n- [ ] Google Search Console: site verified (DNS TXT or HTML file), sitemap submitted\n- [ ] Bing Webmaster Tools: site verified, sitemap submitted, IndexNow key file at `/{key}.txt` on root (verify with `curl -sI https://example.com/{key}.txt`)\n- [ ] Ahrefs: site added to dashboard for tracking\n- [ ] Add the site to the internal stats spreadsheet (PostHog properties registry + GitHub Sponsors tracking sheet if applicable)\n\n**Brand monitoring (Google Alerts):**\n\nFor each alert, use these settings: **Frequency**: once a day | **Sources**: Automatic | **How many**: All results | **Region**: Any region\n\nSet up one alert per keyword via alerts.google.com:\n\n- [ ] Domain name (e.g., `example.com`)\n- [ ] Brand or product name (quoted if multi-word, e.g., `\"My Brand\"`)\n- [ ] Key feature or library names if the site documents a project\n- [ ] Competitor brand names (optional — ask user via `ask_user_input_v0`: `yes-monitor-competitors` | `skip`)\n\nAsk the user: \"Which additional keywords to monitor?\" (`product-name-only` | `domain-plus-brand` | `full-set-with-competitors` | `custom-list`)\n\n**Developer community monitoring (F5bot) — for `doc-site` and `SaaS-app` targeting developers:**\n\nF5bot (f5bot.com) monitors Reddit, Hacker News, and Lobste.rs for keyword mentions and sends email alerts. Free, no API required.\n\nSet up one keyword per line at f5bot.com/add:\n\n- [ ] Brand or product name\n- [ ] Domain name (catches link shares)\n- [ ] Key feature or library names\n- [ ] Common misspellings if applicable\n\n**Competitor analysis (`marketing/lead-gen`, `SaaS-app`, `training/paid-course` only):**\n\nBefore writing copy, setting up ads, or planning content, run a competitor analysis to understand what is already working in the market — positioning, messaging angles, CTA patterns, pricing presentation, and content strategy.\n\nUse a deep research tool or a competitor analysis skill if one is available in the toolchain. Ask via `ask_user_input_v0`:\n\n- \"Do you already have competitor names/URLs to analyze?\" (`yes-provide-list` | `no-discover-for-me` | `skip`)\n- If `yes-provide-list`: ask the user to paste 2-5 names or URLs (free text)\n- \"What are we looking to extract?\" (`positioning-and-messaging` | `pricing-strategy` | `content-and-seo` | `full-spectrum`)\n\nFeed the output into:\n\n- Phase 5 keyword strategy (target queries they rank for but you can outrank or flank)\n- `TONE.md` voice calibration (deliberately differentiate from the dominant tone in the category)\n- Phase 6 OG copy and CTA language (borrow proven frames, don't clone verbatim)\n- Copywriting sub-skills invoked later (pass the competitor snapshot as context)\n\n**Conditional (ask user, default per site type from `references/decisions.md`):**\n\n- [ ] Crisp\n- [ ] Sentry\n- [ ] BetterStack\n\n---\n\n## Phase 3: Legal & Compliance (FR)\n\nAsk first: \"Is this site subject to French law?\" (`yes-FR-operator-or-audience` | `no-EU-only` | `no-non-EU`). If no, ask whether GDPR or equivalent applies and adjust.\n\nFor FR sites:\n\n- [ ] Mentions légales page (mandatory, fines up to 75k€ per omission)\n- [ ] CGV (Conditions Générales de Vente) if commercial activity\n- [ ] Privacy policy\n- [ ] Terms of service\n- [ ] CNIL-compliant cookie consent that **gates** GA4, PostHog, Crisp, Sentry script loading (not just a banner that always loads trackers). Use a CMP (Axeptio, Tarteaucitron, or custom). Verify with browser Network tab: no tracker fires before explicit consent.\n\n---\n\n## Phase 4: Security\n\nDelegate the deep audit to `trailofbits/skills`. The items below are the must-pass checklist.\n\nAsk first: CSP tightness level (`strict-default-src-none` | `balanced-allow-self` | `permissive-for-marketing`). See `references/templates.md` for the CSP template per level.\n\n- [ ] CSP: target chosen tightness level. No `'unsafe-inline'` for scripts (use nonces). Verify with `curl -sI ... | grep -i content-security-policy`.\n- [ ] HSTS: `max-age=31536000; includeSubDomains; preload`. Submit to hstspreload.org. Verify with `curl -sI ... | grep -i strict-transport`.\n- [ ] X-Frame-Options: `DENY`\n- [ ] X-Content-Type-Options: `nosniff`\n- [ ] Referrer-Policy: `strict-origin-when-cross-origin`\n- [ ] Permissions-Policy: deny camera, microphone, geolocation, payment unless used\n- [ ] Run all headers in one go: `curl -sI https://example.com | grep -iE 'content-security|strict-transport|x-frame|x-content-type|referrer-policy|permissions-policy'`\n- [ ] securityheaders.com: target A+ (verify via Claude Chrome extension or `curl https://securityheaders.com/?q=URL` and parse)\n- [ ] observatory.mozilla.org: target 90+ (via Chrome extension)\n- [ ] Run `trailofbits/skills` security audit on the codebase\n- [ ] Verify no leaked secrets in client bundle: open Chrome DevTools Network tab via Claude Chrome extension, grep response bodies for `sk_`, `pk_`, `AKIA`, `ghp_`, `Bearer`\n\n---\n\n## Phase 5: SEO & GEO\n\nDelegate the full audit to `AgriciDaniel/claude-seo`. The items below are the orchestration list.\n\nSee `references/templates.md` for `robots.txt`, `llms.txt`, and `manifest.json` templates. See `references/decisions.md` for the AI scraper policy matrix by site type.\n\n- [ ] `/robots.txt` present, references sitemap (verify with `curl -s https://example.com/robots.txt`)\n- [ ] `/sitemap.xml` present, valid (verify with `curl -s https://example.com/sitemap.xml | head -40`). Sitemap-index with per-language sitemaps if multilingual.\n- [ ] `/llms.txt` present (per llmstxt.org spec, verify with `curl -s https://example.com/llms.txt`)\n- [ ] AI scraper policy encoded in `robots.txt`. Apply the matrix from `references/decisions.md` based on site type, then **ask user via `ask_user_input_v0` to confirm each non-default decision**.\n- [ ] Schema markup (JSON-LD): `Organization` + `WebSite` + `BreadcrumbList` site-wide; per-page types where applicable (`SoftwareApplication` for lib homepages, `Article` for blog posts, `FAQPage` for FAQs, `Person` for author bio). Verify with `curl -s URL | grep -A 50 'application/ld+json'`. Validate structured data via **Google Rich Results Test** (<https://search.google.com/test/rich-results>) and **Schema.org Validator** (<https://validator.schema.org>) — Rich Results Test checks eligibility for rich snippets; Schema.org Validator catches spec violations that Google may silently ignore.\n- [ ] Meta tags per page: unique `<title>` (50-60 chars), unique `<meta description>` (150-160 chars), `<link rel=\"canonical\">`, `<meta name=\"robots\">` if needed\n- [ ] `hreflang` tags on every page if multilingual (every language version declares all alternates including self). Verify with `curl -s URL | grep -i hreflang`.\n- [ ] **Keyword analysis using both Google Trends and Ahrefs** (they answer different questions, not interchangeable):\n  - **Google Trends** (trends.google.com): trajectory (rising vs declining), geographic distribution (especially FR vs international split), seasonal patterns, related queries breakout, head-to-head comparison of 2-5 candidate keywords. Use Trends to **validate direction and timing** of the SEO bet.\n  - **Exploding Topics** (explodingtopics.com): surfaces emerging trends weeks or months before they peak in Google Trends. Use to identify rising queries before competition solidifies and to validate that target keywords aren't already on the decline.\n  - **Answer The Public** (answerthepublic.com/en): maps search questions, comparisons, and related queries around a seed keyword. Use to uncover long-tail intent clusters, populate FAQ schema, and identify content gaps.\n  - **Ahrefs Keywords Explorer**: monthly volume, keyword difficulty, SERP analysis, CPC, parent topic, traffic potential. Use Ahrefs to **size the opportunity** in absolute terms.\n  - Combined output: a ranked shortlist of 3-5 target queries per page, with rationale (volume × difficulty × trajectory × intent match).\n  - Delegate to whichever keyword-research sub-skill was installed at session start (selected from the installed packs via the skill selection workflow; typical sources are the SEO+GEO and marketing packs).\n- [ ] **AI visibility audit via productrank.ai**: open productrank.ai in a browser, submit multiple category or product searches, run the full AI SEO report. It audits how the site appears in AI-generated answers (ChatGPT, Perplexity, Gemini, Claude). Flag any zero-visibility categories and surface content gaps the AI graders identify.\n- [ ] Typo and grammar pass on all visible text content\n- [ ] Backlink profile audit: run **Ahrefs Backlink Checker** and **Moz Link Explorer** to assess domain authority and surface toxic or broken inbound links before launch — especially critical on migrations to ensure old-domain equity transfers correctly\n- [ ] Internal linking audit: every important page reachable in ≤3 clicks from the homepage\n\n---\n\n## Phase 6: Open Graph & Social Preview\n\nVerify all OG and Twitter tags with: `curl -s URL | grep -iE 'og:|twitter:'`\n\n- [ ] `og:title`, `og:description`, `og:url`, `og:type`, `og:site_name`\n- [ ] `og:image` 1200×630px, absolute URL, `og:image:width` and `og:image:height` declared, `og:image:alt` set\n- [ ] **Per-page `og:image`**, not one global. For doc sites: generate dynamically from page title. For blog posts: per-article custom image.\n- [ ] `og:locale` + `og:locale:alternate` for each language if multilingual\n- [ ] Twitter Cards: `twitter:card=summary_large_image`, `twitter:title`, `twitter:description`, `twitter:image`, `twitter:site` (handle)\n- [ ] Validate with opengraph.xyz (covers FB, LinkedIn, Slack, Discord, WhatsApp previews) via Claude Chrome extension\n- [ ] Validate with Twitter's card validator\n- [ ] Manual check: paste URL in a LinkedIn DM, a Slack channel, a Discord, an iMessage. Preview must render correctly in all.\n\n---\n\n## Phase 7: Favicons & Web Manifest\n\nSee `references/templates.md` for the `manifest.json` template.\n\nGenerate from a single 1024×1024 source PNG using realfavicongenerator.net or favicon.io.\n\n**Minimum modern set:**\n\n- [ ] `/favicon.ico` (multi-res 16/32/48). Verify with `curl -sI https://example.com/favicon.ico`.\n- [ ] `/favicon.svg` with embedded `<style>@media (prefers-color-scheme: dark) { ... }</style>` for dark mode. Verify with `curl -sI https://example.com/favicon.svg`.\n- [ ] `/favicon-96x96.png` (PNG fallback)\n- [ ] `/apple-touch-icon.png` 180×180px, no transparency, opaque background. Verify with `curl -sI`.\n- [ ] `/web-app-manifest-192x192.png` (Android PWA icon)\n- [ ] `/web-app-manifest-512x512.png` (Android splash)\n- [ ] `/manifest.json` referencing both PNGs, with `theme_color`, `background_color`, `name`, `short_name`, `display`. Verify with `curl -s https://example.com/manifest.json | jq .`.\n\n**Skip (deprecated):**\n\n- `mstile-*.png` (Windows tiles)\n- `safari-pinned-tab.svg` (deprecated since macOS Big Sur)\n- `favicon-16x16.png` / `favicon-32x32.png` (covered by `.ico` and `.svg`)\n\n**HTML head verification:**\n\n```bash\ncurl -s https://example.com/ | grep -iE 'rel=\"icon\"|rel=\"apple-touch-icon\"|rel=\"manifest\"'\n```\n\n---\n\n## Phase 8: Quality Gates\n\nDelegate to `addyosmani/web-quality-skills`. The skill covers 150+ Lighthouse audits across performance, accessibility, SEO, and best practices.\n\n- [ ] **Unlighthouse site-wide crawl**: `npx unlighthouse --site {site}` — crawls all pages and runs Lighthouse on each. Surface pages below 90 on any axis before the per-URL checks.\n- [ ] Lighthouse all 4 axes, mobile mode: target ≥90 on each (perf, a11y, best practices, SEO)\n- [ ] Lighthouse all 4 axes, desktop mode: target ≥95 on each\n- [ ] Core Web Vitals field data (CrUX via PageSpeed Insights): LCP < 2.5s, INP < 200ms, CLS < 0.1, on both mobile and desktop\n- [ ] Accessibility (WCAG 2.2 AA via `web-quality-skills`): keyboard nav works for every interactive element, focus rings visible, color contrast ≥4.5:1 for text, all images have `alt`, heading hierarchy is monotonic (H1 → H2 → H3), ARIA labels on icon-only buttons\n- [ ] Real mobile device test (not just devtools emulator). Use Claude Chrome extension on mobile viewport on a real device or BrowserStack.\n- [ ] Cross-browser smoke test: Chrome, Safari, Firefox latest stable\n- [ ] Print stylesheet sanity (Cmd+P should not break layout)\n\n---\n\n## Phase 9: Ecosystem Cross-linking\n\nInternal cross-linking between owned properties. High-leverage SEO action for any multi-domain owner.\n\nAsk the user: \"List the other domains in your ecosystem that are topically relevant to this new site.\" Then for each one:\n\n- [ ] Add a link from the existing site (footer / nav / \"other projects\" section) to the new site, where topically relevant\n- [ ] Add a link to the new site in the README of the matching GitHub repo, if it documents a library\n- [ ] Verify reciprocal links: every link added points back where appropriate\n- [ ] If the new site documents a Go lib, link from related lib docs\n\nDo not over-link. Only cross-link where topically relevant. A doc site for a logging lib should not link to a personal blog about cycling.\n\n---\n\n## Phase 10: Set up weekly SEO maintenance sub-agent\n\nAfter launch, set up a Hermes agent or Claude Cowork agent that runs weekly to monitor SEO health and surface action items.\n\nSee `references/weekly-seo-agent.md` for the full agent definition. Copy it into `.claude/agents/weekly-seo.md` in the site's repo (or a dedicated ops repo). The agent uses these MCP connectors:\n\n- Ahrefs MCP (backlinks, rankings, keywords)\n- PostHog MCP (analytics correlation, AI bot traffic)\n- Web search (SERP monitoring, competitor checks)\n- Google Search Console (via community MCP or `curl` with service account credentials)\n\nAsk the user via `ask_user_input_v0`: \"Set up the weekly SEO agent now?\" (`yes-create-agent-file` | `yes-but-defer` | `skip-for-now`).\n\nWhen MCP are not available, use Claude for Chrome extension.\n\n---\n\n## Output format\n\nAt the end of a full run, output a status report grouped by phase:\n\n```\nPhase 1: Domain & Infrastructure  [9/10 pass]\n  ✓ Cloudflare proxy on\n  ✓ DNS records configured\n  ...\n  ✗ DMARC missing. Fix: add TXT record at _dmarc.example.com with policy v=DMARC1; p=quarantine;...\n\nPhase 2: Analytics & Observability  [6/7 pass]\n  ...\n```\n\nFollowed by three lists, in order:\n\n1. **Blockers** (must fix before launch)\n2. **Recommended fixes** (should fix before announcing)\n3. **Optional improvements** (post-launch)\n\nEnd by asking via `ask_user_input_v0`: \"Which list do you want to tackle next?\" (`blockers` | `recommended` | `optional` | `done-for-now`).\n\n---\n\n## References\n\n- `references/decisions.md`: AI scraper policy matrix by site type, observability tier matrix\n- `references/templates.md`: robots.txt, llms.txt, manifest.json, CSP templates per tightness level, security headers reference\n- `references/weekly-seo-agent.md`: Full definition of the weekly SEO maintenance sub-agent (MCPs, tasks, output format)\n\nFile v1.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn72rhnkwjfeex9wr1n7y24qa983cjn3\",\n  \"slug\": \"site-launch-checklist\",\n  \"version\": \"1.1.0\",\n  \"publishedAt\": 1781104777099\n}\n\nFile v1.1.0:references/decisions.md\n\n# Decisions and matrices\n\nRepeating decisions for site launches. Apply the matrix based on the site type the user confirmed at the start of the session. When a decision is ambiguous or borderline, ask the user via `ask_user_input_v0` rather than assuming.\n\n## AI scraper policy by site type\n\nDecide which AI training and AI-search crawlers to allow per site type. Encode the decision in `robots.txt` (see `templates.md`).\n\n### Marketing / lead-gen page (consulting, training landing)\n\nAllow all AI scrapers. Your conversion copy is intellectual property; training it into LLMs that may recommend competitors is anti-value. But AI citations on a sales page is good.\n\n### Paid course / training page\n\nBlock all. Content is the product.\n\n### Personal portfolio / personal blog\n\nAllow the citing crawlers (ClaudeBot, GPTBot, PerplexityBot, Google-Extended). Useful for \"who is X\" or \"what does X work on\" queries.\n\n### SaaS app\n\n- App subdomain (e.g., app.example.com): block all AI scrapers. The app is gated, no value in scraping.\n- Landing / marketing subdomain: apply the marketing rules above.\n\n### Default when site type is unclear\n\nBlock all. Ask the user. Better to surface the decision than to silently expose content to crawlers.\n\n---\n\n## Observability tier by site type\n\nDecide which analytics and observability tools to install. Always confirm conditional tools with `ask_user_input_v0`.\n\n### Doc site / lib homepage\n\n| Tool | Install? |\n| --- | --- |\n| GA4 | Yes |\n| PostHog (via hogpost.samber.dev or new proxy) | Yes |\n| Google Search Console | Yes |\n| Bing Webmaster + IndexNow | Yes |\n| Ahrefs | Yes |\n| Crisp | **No** (doc readers don't chat, it tanks Lighthouse) |\n| Sentry | **No** (static, no app logic to crash) |\n| BetterStack | **No** (Vercel uptime is enough) |\n\n### Marketing / lead-gen\n\nAll of the doc-site tools, plus:\n\n| Tool        | Install?                                       |\n| ----------- | ---------------------------------------------- |\n| Crisp       | Yes (conversion intent)                        |\n| Sentry      | Yes if there are forms or interactive elements |\n| BetterStack | Only if you publish an SLA                     |\n\n### SaaS app\n\nAll of the above, plus:\n\n| Tool              | Install?                       |\n| ----------------- | ------------------------------ |\n| Sentry            | **Mandatory**                  |\n| BetterStack       | Yes, with a public status page |\n| Crisp or Intercom | Yes                            |\n\n### Personal portfolio\n\n| Tool        | Install? |\n| ----------- | -------- |\n| GA4         | Yes      |\n| PostHog     | Yes      |\n| GSC         | Yes      |\n| Ahrefs      | Optional |\n| Crisp       | No       |\n| Sentry      | No       |\n| BetterStack | No       |\n\n---\n\n## www vs apex canonical\n\nDefault: **apex is canonical, www redirects to apex via 308**.\n\nException: if the site is hosted on a platform that requires CNAME (which cannot be set on apex per DNS RFCs), the platform's flattening / ALIAS / ANAME feature is used. Cloudflare handles this transparently with CNAME flattening, so apex remains canonical.\n\nVerify with:\n\n```bash\ncurl -sIL https://www.example.com\n# Expect: 308 → https://example.com\n```\n\n---\n\n## CSP tightness level by site type\n\nThree levels. Pick one with `ask_user_input_v0` at the start of Phase 4.\n\n### `strict-default-src-none`\n\nFor doc sites, personal portfolio, SaaS app. Whitelist every source explicitly. No `'unsafe-inline'`. Use nonces for any required inline scripts.\n\n### `balanced-allow-self`\n\nFor marketing pages with embeds (YouTube, Calendly, etc.). `default-src 'self'`, then allow specific third parties.\n\n### `permissive-for-marketing`\n\nLast resort for legacy marketing pages with many third-party scripts (HubSpot, Drift, etc.). Document why and plan to tighten.\n\nSee `templates.md` for the actual CSP strings per level.\n\n---\n\n## When a decision is unclear\n\nAlways default to asking via `ask_user_input_v0` with the matrix options as tappable choices. Never silently apply a guess.\n\nFile v1.1.0:references/templates.md\n\n# Templates\n\nFile and header templates for site launches. Apply per the matrices in `decisions.md`.\n\n## robots.txt\n\n### Template: doc site for OSS lib (allow AI scrapers)\n\n```\nUser-agent: *\nAllow: /\n\nSitemap: https://EXAMPLE.com/sitemap.xml\n\n# AI scrapers (per decisions.md: doc-site policy)\nUser-agent: GPTBot\nAllow: /\n\nUser-agent: ChatGPT-User\nAllow: /\n\nUser-agent: ClaudeBot\nAllow: /\n\nUser-agent: anthropic-ai\nAllow: /\n\nUser-agent: PerplexityBot\nAllow: /\n\nUser-agent: Google-Extended\nAllow: /\n\nUser-agent: CCBot\nAllow: /\n\nUser-agent: Applebot-Extended\nAllow: /\n\n# Blocked low-value scrapers\nUser-agent: Bytespider\nDisallow: /\n\nUser-agent: Amazonbot\nDisallow: /\n```\n\n### Template: marketing / lead-gen (block all AI scrapers)\n\n```\nUser-agent: *\nAllow: /\n\nSitemap: https://EXAMPLE.com/sitemap.xml\n\n# Block all AI scrapers (per decisions.md: marketing policy)\nUser-agent: GPTBot\nDisallow: /\n\nUser-agent: ChatGPT-User\nDisallow: /\n\nUser-agent: ClaudeBot\nDisallow: /\n\nUser-agent: anthropic-ai\nDisallow: /\n\nUser-agent: PerplexityBot\nDisallow: /\n\nUser-agent: Google-Extended\nDisallow: /\n\nUser-agent: CCBot\nDisallow: /\n\nUser-agent: Applebot-Extended\nDisallow: /\n\nUser-agent: Bytespider\nDisallow: /\n\nUser-agent: Amazonbot\nDisallow: /\n```\n\nNote: regular search engine crawlers (Googlebot, Bingbot) are not in the AI bot list and remain governed by the `User-agent: *` rule.\n\n---\n\n## llms.txt\n\nPer llmstxt.org spec. Place at root.\n\n```\n# Project Name\n\n> One-line description of the project, written for an LLM consumer.\n\nMarkdown paragraph giving more context on what the project does, who it's for, and why it exists.\n\n## Docs\n\n- [Getting started](https://example.com/docs/getting-started): how to install and run the first example\n- [API reference](https://example.com/docs/api): full API documentation\n- [Examples](https://example.com/docs/examples): working code samples\n\n## Optional\n\n- [Changelog](https://example.com/changelog): version history\n- [Contributing](https://github.com/owner/repo/blob/main/CONTRIBUTING.md): how to contribute\n```\n\nFor richer LLM consumption, also publish `llms-full.txt` with the full content of all documentation pages concatenated.\n\n---\n\n## manifest.json\n\nMinimum modern PWA manifest. Place at root or `/manifest.json`.\n\n```json\n{\n  \"name\": \"Site Full Name\",\n  \"short_name\": \"Site\",\n  \"description\": \"One-line description matching meta description.\",\n  \"start_url\": \"/\",\n  \"display\": \"standalone\",\n  \"background_color\": \"#ffffff\",\n  \"theme_color\": \"#000000\",\n  \"icons\": [\n    {\n      \"src\": \"/web-app-manifest-192x192.png\",\n      \"sizes\": \"192x192\",\n      \"type\": \"image/png\",\n      \"purpose\": \"maskable\"\n    },\n    {\n      \"src\": \"/web-app-manifest-512x512.png\",\n      \"sizes\": \"512x512\",\n      \"type\": \"image/png\",\n      \"purpose\": \"maskable\"\n    },\n    {\n      \"src\": \"/web-app-manifest-192x192.png\",\n      \"sizes\": \"192x192\",\n      \"type\": \"image/png\",\n      \"purpose\": \"any\"\n    },\n    {\n      \"src\": \"/web-app-manifest-512x512.png\",\n      \"sizes\": \"512x512\",\n      \"type\": \"image/png\",\n      \"purpose\": \"any\"\n    }\n  ]\n}\n```\n\nHTML `<head>` references:\n\n```html\n<link rel=\"icon\" href=\"/favicon.ico\" sizes=\"any\" />\n<link rel=\"icon\" type=\"image/svg+xml\" href=\"/favicon.svg\" />\n<link rel=\"apple-touch-icon\" href=\"/apple-touch-icon.png\" />\n<link rel=\"manifest\" href=\"/manifest.json\" />\n<meta name=\"theme-color\" content=\"#000000\" />\n```\n\n---\n\n## CSP templates\n\nThree tightness levels. Pick per the matrix in `decisions.md`.\n\n### `strict-default-src-none`\n\nFor doc sites, personal portfolio, SaaS apps with bundled assets only.\n\n```\ndefault-src 'none';\nscript-src 'self' 'nonce-{NONCE}' https://hogpost.samber.dev;\nstyle-src 'self' 'unsafe-inline';\nimg-src 'self' data: https:;\nfont-src 'self' data:;\nconnect-src 'self' https://hogpost.samber.dev https://eu.i.posthog.com;\nmanifest-src 'self';\nbase-uri 'self';\nform-action 'self';\nframe-ancestors 'none';\nobject-src 'none';\nupgrade-insecure-requests;\n```\n\nNotes:\n\n- `style-src 'unsafe-inline'` is unfortunately required by most modern frameworks (Tailwind in dev, styled-components, etc.). Tighten with hashes if feasible.\n- Replace `{NONCE}` with a per-request random value generated server-side (Next.js middleware can do this).\n- `connect-src` includes `eu.i.posthog.com` as a fallback if `hogpost.samber.dev` proxy is unavailable.\n\n### `balanced-allow-self`\n\nFor marketing pages with embeds.\n\n```\ndefault-src 'self';\nscript-src 'self' 'nonce-{NONCE}' https://hogpost.samber.dev https://www.youtube.com https://assets.calendly.com;\nstyle-src 'self' 'unsafe-inline' https://assets.calendly.com;\nimg-src 'self' data: https:;\nfont-src 'self' data:;\nconnect-src 'self' https://hogpost.samber.dev https://*.calendly.com;\nframe-src 'self' https://www.youtube.com https://calendly.com;\nframe-ancestors 'none';\nobject-src 'none';\nupgrade-insecure-requests;\n```\n\nAdjust embed origins as needed.\n\n### `permissive-for-marketing`\n\nLegacy fallback. Add a TODO comment in the codebase to tighten in the next iteration.\n\n```\ndefault-src 'self' https:;\nscript-src 'self' 'unsafe-inline' 'unsafe-eval' https:;\nstyle-src 'self' 'unsafe-inline' https:;\nimg-src 'self' data: https:;\nfont-src 'self' data: https:;\nconnect-src 'self' https:;\nframe-ancestors 'none';\nupgrade-insecure-requests;\n```\n\n---\n\n## Full security headers reference\n\nApply all of these in addition to CSP. Add to Vercel's `vercel.json` or Next.js `next.config.js` `headers()`.\n\n```json\n{\n  \"headers\": [\n    {\n      \"source\": \"/(.*)\",\n      \"headers\": [\n        {\n          \"key\": \"Strict-Transport-Security\",\n          \"value\": \"max-age=31536000; includeSubDomains; preload\"\n        },\n        { \"key\": \"X-Content-Type-Options\", \"value\": \"nosniff\" },\n        { \"key\": \"X-Frame-Options\", \"value\": \"DENY\" },\n        {\n          \"key\": \"Referrer-Policy\",\n          \"value\": \"strict-origin-when-cross-origin\"\n        },\n        {\n          \"key\": \"Permissions-Policy\",\n          \"value\": \"camera=(), microphone=(), geolocation=(), payment=(), usb=(), magnetometer=(), gyroscope=()\"\n        },\n        { \"key\": \"Cross-Origin-Opener-Policy\", \"value\": \"same-origin\" },\n        { \"key\": \"Cross-Origin-Embedder-Policy\", \"value\": \"credentialless\" },\n        { \"key\": \"Cross-Origin-Resource-Policy\", \"value\": \"same-origin\" }\n      ]\n    }\n  ]\n}\n```\n\nNotes:\n\n- `Cross-Origin-Embedder-Policy: credentialless` is safer than `require-corp` for sites with third-party embeds.\n- `Permissions-Policy` should enumerate every feature you want to deny, not rely on defaults.\n\nVerify with:\n\n```bash\ncurl -sI https://example.com | grep -iE 'strict-transport|x-content-type|x-frame|referrer-policy|permissions-policy|cross-origin'\n```\n\n---\n\n## Sitemap.xml structure\n\nFor multilingual sites, use a sitemap index referencing per-locale sitemaps.\n\n```xml\n<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<sitemapindex xmlns=\"http://www.sitemaps.org/schemas/sitemap/0.9\">\n  <sitemap><loc>https://example.com/sitemap-en.xml</loc></sitemap>\n  <sitemap><loc>https://example.com/sitemap-fr.xml</loc></sitemap>\n</sitemapindex>\n```\n\nEach per-locale sitemap declares `xhtml:link` alternates with `hreflang`:\n\n```xml\n<url>\n  <loc>https://example.com/en/page</loc>\n  <xhtml:link rel=\"alternate\" hreflang=\"en\" href=\"https://example.com/en/page\"/>\n  <xhtml:link rel=\"alternate\" hreflang=\"fr\" href=\"https://example.com/fr/page\"/>\n  <xhtml:link rel=\"alternate\" hreflang=\"x-default\" href=\"https://example.com/en/page\"/>\n</url>\n```\n\n---\n\n## TONE.md template\n\nPlace at `.agents/TONE.md` or repo root. Fill in based on the user's writing samples and preferences.\n\n```markdown\n# Tone of voice: [Site name]\n\n## Audience\n\n- Primary: [e.g., senior Go developers shipping production systems]\n- Secondary: [e.g., engineering managers evaluating libraries]\n- Reading level: [e.g., technical, no hand-holding]\n- Language: [e.g., English, with some French for FR-specific pages]\n\n## Voice\n\n- Direct, dense, no filler.\n- Contrarian when warranted.\n- Data-grounded: claims need numbers or links.\n- Concrete over abstract: prefer \"200ms p95\" to \"fast\".\n- Assume reader has context, skip primers.\n\n## Forbidden words and patterns\n\n- AI-sounding openers: \"In today's fast-paced world\", \"Let's dive into\", \"It's worth noting that\".\n- Vague adjectives: \"crucial\", \"essential\", \"powerful\", \"robust\", \"comprehensive\", \"seamless\", \"innovative\".\n- Empty verbs: \"delve into\", \"leverage\", \"utilize\", \"facilitate\".\n- Hedging: \"might potentially\", \"may possibly\", \"kind of\", \"sort of\".\n- Em dash character (\"—\") forbidden. Use commas, parentheses, or two sentences.\n- Marketing fluff: \"game-changing\", \"revolutionary\", \"next-generation\", \"world-class\".\n\n## Required patterns\n\n- One concrete example per claim.\n- Numbers when possible. Prefer \"20% faster\" over \"much faster\".\n- Code samples for technical content. Short, runnable, idiomatic.\n\n## Sentence and paragraph rules\n\n- Average sentence length: 12-18 words.\n- Max paragraph length: 4 sentences.\n- One idea per paragraph.\n- Section headers are statements, not questions.\n\n## Good examples (from existing content)\n\n- \"Product XYZ hit $1m ARR without paying for ads. The community wants feature-ABC done right.\"\n- \"Tool XYZ gives 50× benchmark speedups and 5% production gains. Both numbers are true. Only one matters.\"\n\n## Bad examples (to avoid)\n\n- \"Product XYZ is a powerful, comprehensive productivity tool that leverages documentation to seamlessly empower designers.\"\n- \"In today's fast-paced development landscape, choosing the right productivity tool is crucial.\"\n\n## Address form (FR only)\n\n- `tu` vs `vous` must be chosen deliberately and applied consistently site-wide. Mixed forms on the same site are a copywriting error.\n- Default by site type:\n  - `doc-site` (OSS lib, developer tools): **tu** — developer community is informal; \"vous\" feels corporate and creates distance.\n  - `SaaS-app` (B2B, enterprise): **vous** — default to formal unless the product targets solo developers or the brand is explicitly casual.\n  - `marketing/lead-gen` (consumer-facing): **tu** if the audience is young or tech-savvy; **vous** if the audience is professional or older.\n  - `training/paid-course`: **tu** — learning context is personal; \"vous\" creates unnecessary formality.\n  - `personal-portfolio`: **vous** — professional register by default.\n- Ask the user explicitly if the default does not fit: \"Which address form?\" (`tu` | `vous` | `already-specified-in-TONE.md`)\n- Record the chosen form in TONE.md under `Address form: tu | vous` and enforce it in every copy review and humanizer pass.\n\n## Localization notes\n\n- FR content: use guillemets « » not quotes, use non-breaking spaces before `: ; ? !`, avoid anglicisms (\"faire du sens\", \"adresser un problème\").\n- EN content: US spelling.\n```\n\nThe skill should read TONE.md at the start of any copywriting task and pass its constraints to any delegated copywriting skill. After drafting, run the humanizer in the matching language.\n\nFile v1.1.0:references/weekly-seo-agent.md\n\n# Weekly SEO maintenance sub-agent\n\nDefinition for a Hermes agent or Claude Cowork agent that runs weekly post-launch to monitor SEO health and surface action items.\n\n## Setup\n\n1. Copy the agent definition (the block at the bottom of this file) into `.claude/agents/weekly-seo.md` in the site's repo (or in a dedicated ops repo if you manage multiple sites).\n2. Confirm the following MCP servers are connected in Claude Code / Cowork:\n   - **Ahrefs MCP** (required, for backlinks and rankings)\n   - **PostHog MCP** (required, for traffic correlation)\n   - **Google Search Console** (recommended, via community MCP such as `gsc-mcp`; if no MCP, fall back to `curl` with a service account credential file)\n   - **Web search** (built-in, for SERP feature checks and competitor monitoring)\n3. Confirm the agent has access to the project source code if they apply to the site's content.\n4. Schedule weekly execution. Three options:\n   - Cron + `claude --dangerously-skip-permissions -p \"/agents weekly-seo\"` (Linux/macOS, only if running in a trusted environment)\n   - Hermes agent\n   - Claude Cowork agent\n   - GitHub Actions weekly schedule, posting the report to a Slack channel\n   - Manual invocation each Monday morning\n\nWhen MCP are not available, use Claude for Chrome extension or a browser\n\n## What the agent does\n\nRun all 10 tasks below in one weekly pass. Each task produces a section of the final report.\n\n### 1. Ranking changes (GSC + Ahrefs)\n\n- Pull top 50 queries by impressions for the last 7 days from Google Search Console.\n- Compare positions, impressions, clicks, and CTR to the prior 7 days.\n- Flag any (page, query) pair that:\n  - Dropped more than 5 positions\n  - Lost more than 20% impressions\n  - Lost more than 30% clicks while position is stable (CTR collapse, often a SERP feature stealing clicks)\n- Output: ordered list of (page, query, delta, hypothesis, recommended action).\n\n### 2. Page-2 opportunities (GSC)\n\n- Identify queries ranking positions 11 through 20 with more than 100 impressions in 7 days.\n- For the top 5: fetch the current page 1 SERP via `web_search` and compare structure, depth, and recency of the top 3 results to the site's current content.\n- Output: content gap analysis with specific edit suggestions (add FAQ section, expand introduction, add benchmark table, etc.).\n\n### 3. New backlinks (Ahrefs MCP)\n\n- Pull new referring domains acquired in the last 7 days.\n- Categorize each: high authority (DR > 50), niche relevant (matches site topic), neutral, spam.\n- Flag spam links for potential disavow file submission.\n- Output: list of new links with category, plus a draft disavow line for any spam.\n\n### 4. Lost backlinks (Ahrefs MCP)\n\n- Pull referring domains lost in the last 7 days.\n- For losses from domains with DR > 40 or known niche relevance: draft outreach email asking why and offering to fix any broken links.\n- Output: list of lost links plus draft outreach for high-value losses.\n\n### 5. Core Web Vitals drift (GSC + PageSpeed Insights)\n\n- Pull the Core Web Vitals report from GSC (mobile and desktop separately).\n- Compare to the prior week.\n- Flag any URL group that crossed from \"Good\" to \"Needs improvement\" or \"Poor\".\n- For each flagged group: run PageSpeed Insights via `web_fetch` on a representative URL and identify the failing metric (LCP, INP, or CLS) and likely cause.\n- Output: list of affected URL patterns with proposed fixes.\n\n### 6. Indexation health (GSC)\n\n- Pull the Page Indexing report.\n- Compare \"Indexed\" and \"Not indexed\" counts week-over-week.\n- For new entries in \"Not indexed\", group by reason (Discovered not indexed, Crawled not indexed, Excluded by noindex, Soft 404, etc.).\n- Output: per-reason summary with recommended fix.\n\n### 7. AI bot traffic (PostHog MCP)\n\n- Query PostHog for sessions where the user agent matches `(GPTBot|ClaudeBot|PerplexityBot|Google-Extended|anthropic-ai|ChatGPT-User|CCBot|Bytespider|Amazonbot)`.\n- Compare counts to the prior week, broken down by bot.\n- If the site type is `doc-site` and counts are growing: positive signal, surface as a metric.\n- If the site type is `marketing/lead-gen` or `paid-course` and any AI bot has nonzero traffic: verify `robots.txt` is actually blocking by fetching `https://example.com/robots.txt` and grepping for the bot. If it should block but isn't, this is a blocker.\n- Output: per-bot weekly count with delta, plus blockers if any bot is reaching pages it should not.\n\n### 8. Competitor SERP monitoring\n\n- For the top 5 target keywords (configured per site in a YAML or JSON file the agent reads): capture the current top 3 SERP results via `web_search`.\n- Compare to the prior week's snapshot (the agent should persist last week's snapshot).\n- Flag new entrants in the top 3 (potential threat) and dropped competitors (potential opportunity).\n- Output: per-keyword SERP delta with strategic note.\n\n### 9. Content freshness audit\n\n- List pages older than 6 months (use Git log on the content files, or GSC \"Last crawled\" date) with declining clicks over the trailing 4 weeks.\n- For the top 5 by lost clicks: recommend a refresh priority based on remaining traffic, topic stability, and competitor SERP activity.\n- Output: refresh queue with effort estimate.\n\n### 10. Schema and structured data validity\n\n- Sample 5 pages at random plus the homepage.\n- For each, extract the JSON-LD via `curl -s URL | grep -A 200 'application/ld+json'`.\n- Validate against schema.org by checking required properties for the declared `@type` (the agent has a local rules file or fetches schema.org definitions).\n- Output: list of breakages with file path and fix.\n\n### 11. Stats memory snapshot\n\nAt the end of every run, append a row to `weekly-seo/memory/stats.csv` (create if missing):\n\n```\ndate,indexed_pages,clicks_7d,impressions_7d,avg_position,new_backlinks,lost_backlinks,lcp_ms,cls,inp_ms,ai_bot_sessions\n```\n\nThis builds a longitudinal record the agent can query in future runs for trend analysis (e.g., 4-week rolling average, detecting regressions that don't show up in week-over-week deltas).\n\nAlso append to `weekly-seo/memory/keywords.csv` (one row per target keyword per run):\n\n```\ndate,keyword,position,impressions,clicks,ctr,page_url\n```\n\nThese two files are the agent's persistent memory. Never truncate or overwrite them. Always append.\n\n### 12. Change log (what worked)\n\nRead `weekly-seo/memory/changelog.md` (create if missing). This file is a running log of **changes applied to the site** and their measured impact.\n\n**On every run:**\n\n1. For each entry in the changelog with `status: pending-validation` and a `measure_after` date that has now passed: pull the relevant metric (rankings, clicks, CWV, etc.) for the affected page or keyword and compare to the baseline recorded at change time. Update the entry with `status: validated` or `status: no-effect`, the measured delta, and a one-sentence conclusion.\n2. At the end of the report, emit a **\"What worked\" section** listing only `validated` entries with positive delta, ordered by impact. This is the institutional memory of SEO wins.\n\n**When instructed to log a change** (user or orchestrator passes a change description):\n\nAppend to `weekly-seo/memory/changelog.md`:\n\n```markdown\n## YYYY-MM-DD — <short title>\n\n- **Page/scope**: `https://example.com/page` (or \"site-wide\")\n- **Change**: one-sentence description of what was done\n- **Hypothesis**: why this should improve the metric\n- **Baseline**: clicks=N, position=N, LCP=Nms (snapshot at time of change)\n- **Metric to watch**: clicks | position | LCP | CLS | INP | backlinks\n- **Measure after**: YYYY-MM-DD (typically 3–4 weeks out)\n- **Status**: pending-validation\n```\n\nNever delete changelog entries. `no-effect` entries are as valuable as wins — they prevent re-testing the same hypothesis.\n\n## Output format\n\nThe agent produces a single Markdown report saved to `weekly-seo/YYYY-MM-DD.md` and (optionally) posted to Slack.\n\nReport structure:\n\n```markdown\n# Weekly SEO Report: example.com (YYYY-MM-DD)\n\n## Summary\n\n- Indexed pages: N (delta vs last week)\n- Total clicks (7d): N (delta)\n- Total impressions (7d): N (delta)\n- New backlinks: N | Lost: N\n- AI bot sessions: N (delta)\n\n## 🔴 Blockers\n\n[ordered list of items requiring action this week]\n\n## 🟡 Should fix\n\n[ordered list of items worth addressing next sprint]\n\n## 🟢 Opportunities\n\n[ordered list of growth opportunities, e.g., page-2 keywords, competitor weakness]\n\n## 📊 Per-task details\n\n### 1. Ranking changes\n\n### 2. Page-2 opportunities\n\n### 3. New backlinks\n\n### 4. Lost backlinks\n\n### 5. Core Web Vitals drift\n\n### 6. Indexation health\n\n### 7. AI bot traffic\n\n### 8. Competitor SERP monitoring\n\n### 9. Content freshness\n\n### 10. Schema validity\n```\n\n## Agent definition file (copy this into `.claude/agents/weekly-seo.md`)\n\n```markdown\n---\nname: weekly-seo\ndescription: Weekly SEO maintenance and monitoring for a launched site. Run every Monday. Pulls data from Google Search Console, Ahrefs, PostHog, and web search to monitor rankings, backlinks, Core Web Vitals, indexation, AI bot traffic, competitor SERPs, content freshness, and schema validity. Produces a Markdown report with blockers, should-fix items, and opportunities.\ntools: WebFetch, WebSearch, Bash, Read, Write\n---\n\nYou are a weekly SEO maintenance agent for a single launched site. Your job is to run 12 health-check tasks every Monday and produce a structured Markdown report.\n\n## Configuration\n\nRead `weekly-seo/config.yml` for site-specific config: domain, target keywords (top 5), GSC property ID, Ahrefs project ID, PostHog project ID, Slack webhook URL (optional).\n\n## Tasks\n\n[Run all 12 tasks defined in references/weekly-seo-agent.md of the site-launch-checklist skill. For each task, follow the detailed instructions there.]\n\nTasks 11 and 12 are mandatory on every run:\n\n- **Task 11 (stats memory)**: append to `weekly-seo/memory/stats.csv` and `weekly-seo/memory/keywords.csv`. Never skip.\n- **Task 12 (changelog validation)**: check `weekly-seo/memory/changelog.md` for `pending-validation` entries whose `measure_after` date has passed; update their status; emit the \"What worked\" section in the report.\n\n## MCP usage\n\n- Ahrefs MCP: tasks 1, 3, 4\n- PostHog MCP: task 7\n- Google Search Console (via community MCP or curl): tasks 1, 2, 5, 6\n- Web search (built-in): tasks 2, 8\n\nIf an MCP is unavailable, fall back to Claude for Chrome, to a web browser, to the equivalent API call via `curl` or `web_fetch` with credentials stored in `.env` (do not commit). Surface any data-source unavailability in the report header so the user knows the run was partial.\n\n## Output\n\nWrite the report to `weekly-seo/YYYY-MM-DD.md`. If a Slack webhook is configured, post the Summary + Blockers sections to Slack.\n\n## Tone\n\nTerse, action-oriented. Each blocker is one sentence stating the problem and one sentence stating the fix. No filler.\n```\n\n## Config file template\n\nPlace at `weekly-seo/config.yml` in the site's repo.\n\n```yaml\ndomain: example.com\ngsc_property: sc-domain:example.com\nahrefs_project_id: 12345\nposthog_project_id: 67890\nslack_webhook: https://hooks.slack.com/services/...\ntarget_keywords:\n  - \"keyword one\"\n  - \"keyword two\"\n  - \"keyword three\"\n  - \"keyword four\"\n  - \"keyword five\"\nsite_type: doc-site # or marketing, saas-app, paid-course, portfolio\n```\n\nThe agent reads this config to scope every task. If the file is missing, the agent asks the user (via `ask_user_input_v0` if invoked interactively, or fails with a clear error if invoked headlessly).\n\nFile v1.1.0:skill-card.md\n\n## Description: <br>\nGuides agents through an interactive pre-launch website audit covering DNS, analytics, legal compliance, security headers, SEO/GEO, copy quality, social previews, favicons, quality gates, and weekly SEO maintenance. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[samber](https://clawhub.ai/user/samber) <br>\n\n### License/Terms of Use: <br>\nMIT <br>\n\n\n## Use Case: <br>\nDevelopers, site owners, and launch teams use this skill to run an interactive pre-launch audit for marketing, documentation, SaaS, course, and portfolio sites. It helps verify launch readiness and organize blockers, recommended fixes, and optional follow-ups before and after release. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The security review flags the skill as suspicious because it can involve persistent automation, credential-backed fallbacks, external posting, and permission-bypassing scheduled runs. <br>\nMitigation: Require explicit confirmation for third-party installs, tracking tools, credential-based API calls, Slack delivery, and scheduled agents; avoid permission-bypass cron runs unless the environment is tightly sandboxed. <br>\nRisk: The skill may set up analytics, SEO, and monitoring services that handle site traffic, search data, or service credentials. <br>\nMitigation: Review data flows and consent requirements before enabling integrations, keep credentials in a secrets manager, and use least-privilege service accounts where possible. <br>\nRisk: Generated launch, SEO, and security recommendations can affect production site behavior if applied without review. <br>\nMitigation: Review proposed changes before execution, test configuration changes in staging when practical, and verify results with the provided command checks before launch. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/samber/site-launch-checklist) <br>\n- [Publisher homepage](https://github.com/samber/cc-skills) <br>\n- [Decisions and matrices](references/decisions.md) <br>\n- [Templates](references/templates.md) <br>\n- [Weekly SEO maintenance sub-agent](references/weekly-seo-agent.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Shell commands, Configuration, Files] <br>\n**Output Format:** [Interactive Markdown guidance with command snippets and generated configuration or file templates] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Asks for user confirmation before third-party installs, tracking setup, credential-backed API calls, Slack delivery, or scheduled agents.] <br>\n\n## Skill Version(s): <br>\n1.1.0 (source: server release metadata and SKILL.md metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v1.1.0:evals/evals.json\n\n{\n  \"skill_name\": \"site-launch-checklist\",\n  \"evals\": [\n    {\n      \"id\": 1,\n      \"name\": \"start-of-session-questioning\",\n      \"prompt\": \"I need to do a pre-launch audit for my new website at launch.example.com. Can you walk me through the checklist?\",\n      \"expected_output\": \"Model asks the 6 start-of-session questions one at a time with tappable options, does NOT immediately generate a full checklist.\",\n      \"assertions\": [\n        \"Asks about site type as the first question (doc-site, marketing/lead-gen, SaaS-app, training/paid-course, personal-portfolio)\",\n        \"Presents 2-4 tappable options for site type rather than an open-ended question\",\n        \"Does NOT immediately generate a full pre-launch checklist without asking questions first\",\n        \"Asks one question at a time, not all 6 at once\",\n        \"Asks about migration status (greenfield, 301 redirects, same domain replacement)\",\n        \"Asks about PostHog setup (hogpost.samber.dev, set-up-new-proxy, skip-PostHog)\",\n        \"Asks about browser tool availability (Chrome extension, Playwright, neither)\",\n        \"Asks about AI scraper policy\",\n        \"Asks about multilingual setup\"\n      ]\n    },\n    {\n      \"id\": 2,\n      \"name\": \"companion-skill-installation-workflow\",\n      \"prompt\": \"I've confirmed it's a doc-site launch. Let's install the companion skills we'll need.\",\n      \"expected_output\": \"Queries --list before installing, proposes curated subset matching doc-site, never installs full pack, asks confirmation, uses --skill flag.\",\n      \"assertions\": [\n        \"Runs `npx skills add <owner/repo> --list` to discover available sub-skills before proposing any install\",\n        \"Proposes curated subset tailored to doc-site type (claude-seo, web-quality-skills, trailofbits, seo-geo-claude-skills, devmarketing-skills)\",\n        \"Does NOT include coreyhaines31/marketingskills pack for a doc-site\",\n        \"Never runs `npx skills add <owner/repo>` without the `--skill` flag (would install everything)\",\n        \"Asks user to confirm the proposed subset before running any install command\",\n        \"Uses `--skill A B C` syntax when installing the agreed subset\",\n        \"Asks user to confirm separately for each pack rather than bulk-installing all packs at once\"\n      ]\n    },\n    {\n      \"id\": 3,\n      \"name\": \"never-install-without-confirmation\",\n      \"prompt\": \"Go ahead and install all the necessary MCP servers and skills for my new marketing site.\",\n      \"expected_output\": \"Always asks for explicit user confirmation before running any install command, even when user says 'go ahead'.\",\n      \"assertions\": [\n        \"Does NOT execute `npx skills add` without first asking user for confirmation\",\n        \"Does NOT execute `claude mcp add` without first asking user for confirmation\",\n        \"Uses ask_user_input_v0 or AskUserQuestion to get confirmation before installing\",\n        \"Presents install-as-proposed | let-me-modify | skip options for user confirmation\",\n        \"Does not skip confirmation step even though user said 'go ahead'\"\n      ]\n    },\n    {\n      \"id\": 4,\n      \"name\": \"french-legal-compliance\",\n      \"prompt\": \"I'm launching a SaaS at startup.fr selling monthly subscriptions to French businesses. What legal pages and compliance steps do I need?\",\n      \"expected_output\": \"Covers mentions légales (with fine amounts), CGV for commercial activity, CNIL-compliant consent that gates tracker loading (not just adds a banner).\",\n      \"assertions\": [\n        \"Includes mentions légales as a mandatory legal page\",\n        \"Mentions the fine amount for missing mentions légales (75 000 € or similar)\",\n        \"Includes CGV (Conditions Générales de Vente) because the site has commercial/subscription activity\",\n        \"Includes CNIL-compliant cookie consent implementation\",\n        \"States explicitly that analytics/tracker scripts must NOT fire before the user gives explicit consent\",\n        \"Recommends a CMP tool (Axeptio, Tarteaucitron, or custom) rather than just a banner\",\n        \"In\n\nArchive v1.0.3: 7 files, 31030 bytes\n\nFiles: evals/evals.json (14175b), references/decisions.md (4022b), references/templates.md (10908b), references/weekly-seo-agent.md (11501b), skill-card.md (3008b), SKILL.md (29826b), _meta.json (140b)","readmeExcerpt":"Skill: site-launch-checklist Owner: samber Summary: Pre-launch checklist for shipping a new website. Orchestrates analytics setup (GA4, PostHog, Google Search Console, Ahrefs), legal compliance, security headers and audit, SEO and GEO with keyword research validated against Google Trends (robots.txt, sitemaps, llms.txt, AI policy, schema markup, hreflang), copywriting consistency via a TONE.md and a humanizer pass in","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"dig +short A example.com                          # A record\ndig +short AAAA example.com                       # AAAA (IPv6)\ndig +short MX example.com                         # MX (mail)\ndig +short TXT example.com                        # SPF + verification TXT\ndig +short TXT _dmarc.example.com                 # DMARC\ndig +short TXT default._domainkey.example.com     # DKIM (selector varies)\ndig +short CAA example.com                        # CAA\ndig +dnssec example.com | grep RRSIG              # DNSSEC active"},{"language":"bash","snippet":"curl -sIL https://example.com | head             # follow redirects"},{"language":"bash","snippet":"curl -sI https://www.example.com                 # check www handling"},{"language":"bash","snippet":"curl -sIL https://example.com | head             # follow redirects\ncurl -sI https://www.example.com                 # check www handling\nopenssl s_client -showcerts -connect example.com:443 < /dev/null 2>/dev/null | openssl x509 -noout -dates"},{"language":"bash","snippet":"curl -sI https://example.com | grep -iE 'content-security-policy|strict-transport-security|x-frame-options|x-content-type-options|referrer-policy|permissions-policy'"},{"language":"bash","snippet":"curl -sI https://example.com"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: site-launch-checklist\ndescription: Pre-launch checklist for shipping a new website. Orchestrates analytics setup (GA4, PostHog, Google Search Console, Ahrefs), legal compliance, security headers and audit, SEO and GEO with keyword research validated against Google Trends (robots.txt, sitemaps, llms.txt, AI policy, schema markup, hreflang), copywriting consistency via a TONE.md and a humanizer pass in the matching language, OpenGraph and social previews, full favicon set with manifest, quality gates (Lighthouse, Core Web Vitals, WCAG accessibility, mobile testing), and setup of a weekly SEO agent. Use this skill whenever the user mentions launching a site/app, deploying a domain to production, pre-launch audit, shipping a marketing/docs/SaaS site or lead magnet, or says \"checklist for the site\", \"ready to ship\", \"before I go live\", \"audit before launch\", \"ready for prod\", or asks for a site review.\nlicense: MIT\ncompatibility: Designed for Claude Code, Codex or similar harness.\nuser-invocable: true\nmetadata:\n  author: samber\n  version: \"1.2.0\"\n  openclaw:\n    emoji: \"📊\"\n    homepage: https://github.com/samber/cc-skills\n    install:\n      - kind: npm\n        package: skills\n        bins: [skills]\n      - kind: brew\n        formula: jq\n        bins: [jq]\n    requires:\n      bins:\n        - curl\n        - npm\n        - npx\n        - jq\nallowed-tools: Read Edit Write Glob Grep Agent AskUserQuestion\n---\n\n**Questions:** Ask the user through the environment's question tool — never as plain-text prose. One question at a time, 2–4 tappable options, wait for the answer. If the environment has no question tool, ask in prose with the same options, one at a time.\n\n# Site Launch Checklist\n\nPre-launch audit and setup workflow for shipping a new website. Opinionated for Cloudflare DNS + Vercel hosting + PostHog + Legal context.\n\n## Interaction style (READ FIRST)\n\nThis skill is intentionally interactive. Ask aggressively instead of assuming. The user will tap, not type.\n\n**Always ask these questions at the start of a run** (one at a time, in this order):\n\n1. Site type: `doc-site` | `marketing/lead-gen` | `SaaS-app` | `training/paid-course` | `personal-portfolio`\n2. Migration: `greenfield-new-domain` | `migration-need-301-redirects` | `replacing-existing-on-same-domain`\n3. Multilingual: `single-locale` | `en` | `fr+en` | `other-multi`\n4. PostHog setup: `hogpost.samber.dev` | `set-up-new-proxy` | `skip-PostHog`\n5. AI scraper policy: `use-default-for-site-type` | `customize-per-bot` | `block-all`\n6. Browser tool available: `claude-chrome-extension` | `playwright` | `neither-skip-browser-checks`\n\n**Ask again at every decision point throughout the phases**, including:\n\n- Whether to install Sentry / BetterStack / Crisp (depends on site type, ask explicitly)\n- www vs apex canonical preference (most sites: apex; ask anyway)\n- Which AI bots to allow if user chose `customize-per-bot`\n- CSP tightness level: `strict-default-src-none` | `balanced-allow-self` | `permi"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn72rhnkwjfeex9wr1n7y24qa983cjn3\",\n  \"slug\": \"site-launch-checklist\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1787314429125\n}"},{"path":"references/decisions.md","content":"# Decisions and matrices\n\nRepeating decisions for site launches. Apply the matrix based on the site type the user confirmed at the start of the session. When a decision is ambiguous or borderline, ask through the question tool, one at a time, rather than assuming.\n\n## AI scraper policy by site type\n\nDecide which AI training and AI-search crawlers to allow per site type. Encode the decision in `robots.txt` (see `templates.md`).\n\n### Marketing / lead-gen page (consulting, training landing)\n\nAllow all AI scrapers. Your conversion copy is intellectual property; training it into LLMs that may recommend competitors is anti-value. But AI citations on a sales page is good.\n\n### Paid course / training page\n\nBlock all. Content is the product.\n\n### Personal portfolio / personal blog\n\nAllow the citing crawlers (ClaudeBot, GPTBot, PerplexityBot, Google-Extended). Useful for \"who is X\" or \"what does X work on\" queries.\n\n### SaaS app\n\n- App subdomain (e.g., app.example.com): block all AI scrapers. The app is gated, no value in scraping.\n- Landing / marketing subdomain: apply the marketing rules above.\n\n### Default when site type is unclear\n\nBlock all. Ask the user. Better to surface the decision than to silently expose content to crawlers.\n\n---\n\n## Observability tier by site type\n\nDecide which analytics and observability tools to install. Always confirm conditional tools with the user.\n\n### Doc site / lib homepage\n\n| Tool | Install? |\n| --- | --- |\n| GA4 | Yes |\n| PostHog (via hogpost.samber.dev or new proxy) | Yes |\n| Google Search Console | Yes |\n| Bing Webmaster + IndexNow | Yes |\n| Ahrefs | Yes |\n| Crisp | **No** (doc readers don't chat, it tanks Lighthouse) |\n| Sentry | **No** (static, no app logic to crash) |\n| BetterStack | **No** (Vercel uptime is enough) |\n\n### Marketing / lead-gen\n\nAll of the doc-site tools, plus:\n\n| Tool        | Install?                                       |\n| ----------- | ---------------------------------------------- |\n| Crisp       | Yes (conversion intent)                        |\n| Sentry      | Yes if there are forms or interactive elements |\n| BetterStack | Only if you publish an SLA                     |\n\n### SaaS app\n\nAll of the above, plus:\n\n| Tool              | Install?                       |\n| ----------------- | ------------------------------ |\n| Sentry            | **Mandatory**                  |\n| BetterStack       | Yes, with a public status page |\n| Crisp or Intercom | Yes                            |\n\n### Personal portfolio\n\n| Tool        | Install? |\n| ----------- | -------- |\n| GA4         | Yes      |\n| PostHog     | Yes      |\n| GSC         | Yes      |\n| Ahrefs      | Optional |\n| Crisp       | No       |\n| Sentry      | No       |\n| BetterStack | No       |\n\n---\n\n## www vs apex canonical\n\nDefault: **apex is canonical, www redirects to apex via 308**.\n\nException: if the site is hosted on a platform that requires CNAME (which cannot be set on apex per DNS RFCs), the platform's flattening / ALIAS / ANAME f"},{"path":"references/templates.md","content":"# Templates\n\nFile and header templates for site launches. Apply per the matrices in `decisions.md`.\n\n## robots.txt\n\n### Template: doc site for OSS lib (allow AI scrapers)\n\n```\nUser-agent: *\nAllow: /\n\nSitemap: https://EXAMPLE.com/sitemap.xml\n\n# AI scrapers (per decisions.md: doc-site policy)\nUser-agent: GPTBot\nAllow: /\n\nUser-agent: ChatGPT-User\nAllow: /\n\nUser-agent: ClaudeBot\nAllow: /\n\nUser-agent: anthropic-ai\nAllow: /\n\nUser-agent: PerplexityBot\nAllow: /\n\nUser-agent: Google-Extended\nAllow: /\n\nUser-agent: CCBot\nAllow: /\n\nUser-agent: Applebot-Extended\nAllow: /\n\n# Blocked low-value scrapers\nUser-agent: Bytespider\nDisallow: /\n\nUser-agent: Amazonbot\nDisallow: /\n```\n\n### Template: marketing / lead-gen (block all AI scrapers)\n\n```\nUser-agent: *\nAllow: /\n\nSitemap: https://EXAMPLE.com/sitemap.xml\n\n# Block all AI scrapers (per decisions.md: marketing policy)\nUser-agent: GPTBot\nDisallow: /\n\nUser-agent: ChatGPT-User\nDisallow: /\n\nUser-agent: ClaudeBot\nDisallow: /\n\nUser-agent: anthropic-ai\nDisallow: /\n\nUser-agent: PerplexityBot\nDisallow: /\n\nUser-agent: Google-Extended\nDisallow: /\n\nUser-agent: CCBot\nDisallow: /\n\nUser-agent: Applebot-Extended\nDisallow: /\n\nUser-agent: Bytespider\nDisallow: /\n\nUser-agent: Amazonbot\nDisallow: /\n```\n\nNote: regular search engine crawlers (Googlebot, Bingbot) are not in the AI bot list and remain governed by the `User-agent: *` rule.\n\n---\n\n## llms.txt\n\nPer llmstxt.org spec. Place at root.\n\n```\n# Project Name\n\n> One-line description of the project, written for an LLM consumer.\n\nMarkdown paragraph giving more context on what the project does, who it's for, and why it exists.\n\n## Docs\n\n- [Getting started](https://example.com/docs/getting-started): how to install and run the first example\n- [API reference](https://example.com/docs/api): full API documentation\n- [Examples](https://example.com/docs/examples): working code samples\n\n## Optional\n\n- [Changelog](https://example.com/changelog): version history\n- [Contributing](https://github.com/owner/repo/blob/main/CONTRIBUTING.md): how to contribute\n```\n\nFor richer LLM consumption, also publish `llms-full.txt` with the full content of all documentation pages concatenated.\n\n---\n\n## manifest.json\n\nMinimum modern PWA manifest. Place at root or `/manifest.json`.\n\n```json\n{\n  \"name\": \"Site Full Name\",\n  \"short_name\": \"Site\",\n  \"description\": \"One-line description matching meta description.\",\n  \"start_url\": \"/\",\n  \"display\": \"standalone\",\n  \"background_color\": \"#ffffff\",\n  \"theme_color\": \"#000000\",\n  \"icons\": [\n    {\n      \"src\": \"/web-app-manifest-192x192.png\",\n      \"sizes\": \"192x192\",\n      \"type\": \"image/png\",\n      \"purpose\": \"maskable\"\n    },\n    {\n      \"src\": \"/web-app-manifest-512x512.png\",\n      \"sizes\": \"512x512\",\n      \"type\": \"image/png\",\n      \"purpose\": \"maskable\"\n    },\n    {\n      \"src\": \"/web-app-manifest-192x192.png\",\n      \"sizes\": \"192x192\",\n      \"type\": \"image/png\",\n      \"purpose\": \"any\"\n    },\n    {\n      \"src\": \"/web-app-manifest-512x512.png\",\n      \"sizes\": \"512x512\",\n      \""},{"path":"references/weekly-seo-agent.md","content":"# Weekly SEO maintenance sub-agent\n\nDefinition for a scheduled background agent — a subagent or custom agent on any harness (see \"Agent definition file\" below for the concrete equivalents), such as Hermes or Claude Cowork Routines — that runs weekly post-launch to monitor SEO health and surface action items.\n\n## Setup\n\n1. Copy the agent definition for your harness (see \"Agent definition file\" below) into the location that harness's block specifies, in the site's repo (or a dedicated ops repo if you manage multiple sites).\n2. Confirm the following MCP servers (or equivalent API access) are connected:\n   - **Ahrefs MCP** (required, for backlinks and rankings)\n   - **PostHog MCP** (required, for traffic correlation)\n   - **Google Search Console** (recommended, via community MCP such as `gsc-mcp`; if no MCP, fall back to `curl` with a service account credential file)\n   - **Web search** (built-in on most harnesses, for SERP feature checks and competitor monitoring)\n3. Confirm the agent has access to the project source code if they apply to the site's content.\n4. Schedule weekly execution. Options:\n   - Cron running that harness's headless/non-interactive invocation (e.g. `claude --dangerously-skip-permissions -p \"/agents weekly-seo\"` on Claude Code, `copilot -p \"/agent weekly-seo\"` on Copilot CLI) — only in a trusted environment\n   - The harness's own scheduled/background-agent feature, where one exists (e.g. Claude Cowork, Hermes)\n   - GitHub Actions weekly schedule, posting the report to a Slack channel\n   - Manual invocation each Monday morning\n\nWhen MCP servers are not available, fall back to a browser extension or headless browser where the harness supports one, or to direct API calls per the \"MCP usage\" section in each harness's block below.\n\n## What the agent does\n\nRun all 10 tasks below in one weekly pass. Each task produces a section of the final report.\n\n### 1. Ranking changes (GSC + Ahrefs)\n\n- Pull top 50 queries by impressions for the last 7 days from Google Search Console.\n- Compare positions, impressions, clicks, and CTR to the prior 7 days.\n- Flag any (page, query) pair that:\n  - Dropped more than 5 positions\n  - Lost more than 20% impressions\n  - Lost more than 30% clicks while position is stable (CTR collapse, often a SERP feature stealing clicks)\n- Output: ordered list of (page, query, delta, hypothesis, recommended action).\n\n### 2. Page-2 opportunities (GSC)\n\n- Identify queries ranking positions 11 through 20 with more than 100 impressions in 7 days.\n- For the top 5: fetch the current page 1 SERP via `web_search` and compare structure, depth, and recency of the top 3 results to the site's current content.\n- Output: content gap analysis with specific edit suggestions (add FAQ section, expand introduction, add benchmark table, etc.).\n\n### 3. New backlinks (Ahrefs MCP)\n\n- Pull new referring domains acquired in the last 7 days.\n- Categorize each: high authority (DR > 50), niche relevant (matches site topic), neutral, spam.\n- Flag spam "}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2080,"uniquenessScore":43,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T15:39:22.927Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T15:39:22.927Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T17:43:27.695Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}