web-launcher

releasev0.3.3

Claude Code plugin that diagnoses why a live site is not indexed, traces each reason to the file that causes it, fixes it, and verifies the fix.

0stars
0forks
0watchers
0open issues
owner: voyvodkastatus: CORElanguage: Unknownbranch: mainlicense: MIT Licenseupdated: last push:
agent-skillsclaude-codeclaude-code-plugincloudflare-workersgenerative-engine-optimizationgeogoogle-search-consoleindexingseosite-auditstructured-datasupply-chain-security

README Snapshot

web-launcher

A Claude Code plugin that works out why a live site is not showing up in Google, traces each reason to the file or setting that causes it, fixes it, and verifies the fix.

C1  redirect targets resolve to 200 ............................. OK
C2  live robots.txt matches repo ............... FAIL  a CDN is injecting a managed block
C3  http://example.com/ -> 307 ................. FAIL  temporary; must be 301/308
C7  /index.html returns 200 at 1224 bytes (root: 72763) ... FAIL  SSR bypassed
      and: no canonical
      and: indexable (no noindex)

Every line above is a command that ran, not a rule that was read.

Why

Search Console tells you what — "Page with redirect ×37", "Not found (404) ×3" — and stops there. Turning that into a change in a file is the whole job, and it is where most tooling leaves you: a score, a checklist, a list of symptoms.

Two things make that harder than it looks.

Most of those counts are not defects. A site with 40 canonical URLs whose slashless twins all return a permanent redirect will show ~39 "Page with redirect" entries, and every one of them is Google correctly consolidating. Chasing them changes a working site. This plugin does the arithmetic first and is willing to conclude that nothing is wrong.

Written rules drift from live behaviour. A config comment saying "no 2-hop chain" was wrong for months in the codebase this plugin was built against, because nothing tested it. So the checks here are runnable commands with one-line verdicts, not prose.

Install

/plugin marketplace add voyvodka/claude-plugins
/plugin install web-launcher@voyvodka

Requires Claude Code. The diagnostic checks need curl, grep and a POSIX shell — present on macOS and Linux by default. GEO scoring uses the GeoDaddy MCP server, declared by the plugin and fetched via npx on first use; Search Console access needs a one-time Google OAuth setup, and both are optional.

If GeoDaddy fails to connect. Claude Code gives an MCP server 30 seconds to start. The first npx run of geodaddy-mcp downloads the package and, in its postinstall step, the analyzer binary from GitHub releases — on a slow network that can run past 30 seconds, and the failure is then cached for a while. Start Claude Code once with a longer limit, e.g. MCP_TIMEOUT=90000 claude, so the cache fills; later starts take about a second. The postinstall step ignores its own failure (|| true): if the binary download fails, the server still starts and only analyze_url fails, with "geodaddy binary not found". Clearing the npx cache entry for geodaddy-mcp and starting again re-runs the download.

Usage

Invoke it in a site's repository:

/web-launcher

It picks a mode — launch, audit, or brand-only — scans the project, and produces a severity-ranked gap report before changing anything. For a live site it runs the diagnostic checks first and reports what they returned.

Ask it directly when you already know the question:

why isn't this page indexed? score this site for AI search set up Cloudflare deployment with the apex redirect

What it covers

Area What it does
Diagnosis Maps each Search Console reason to its cause; ten runnable checks for redirect chains, edge-injected robots.txt, temporary redirects, hop counts, sitemap health, canonical mismatches, SSR shell leaks, header delivery, and social cards
Discoverability robots.txt, sitemaps, llms.txt, security.txt, JSON-LD, the full meta head, multi-page canonical and breadcrumb structure
GEO Scores AI-search signals with GeoDaddy, and says where that tool's scoring disagrees with this one — including one finding of its own that is measurably wrong
Deployment Cloudflare Workers: wrangler config, headers, redirects, custom domain and SSL, plus the failure modes that cost real hours
Hardening Dependabot or Renovate, CI audit gates, secret scanning, SBOM, licence sweep, pinned actions

How it works

It reads, then proposes, then asks. Diagnosis is entirely read-only: HTTP requests to the public site and reads of the repository. Nothing is written until you approve a plan.

Search Console access is read-only apart from submitting a sitemap. The API has no request-indexing and no start-validation method, so the plugin says what it changed and hands you the interface link rather than pretending it triggered a recrawl. Credentials stay on your machine.

Every technical claim carries the date it was verified and the source it came from. Reference files are stamped at three levels — verified, partially verified, not re-verified — and the plugin puts itself on a 60-day review clock. An unstamped claim is unverified, and it says so rather than sounding certain.

Limitations

  • Cloudflare only, for deployment. Diagnosis is platform-agnostic and runs over live HTTP, but scaffolding and deploys target Cloudflare Workers. Knowing one platform properly beat knowing four halfway.
  • No content, no analytics, no consent flows. It builds the technical scaffolding; the words and the tracking are someone else's job.
  • No deep application SEO — hreflang for multi-region sites, e-commerce product feeds, and logged-in single-page apps are out of scope.
  • "Crawled – currently not indexed" cannot be closed technically. It is a content and authority question. The plugin names it and does not pretend otherwise.
  • Search Console's coverage report cannot be downloaded. No API exposes it, so the plugin reconstructs a candidate URL set and inspects it — the numbers will approximate the interface, not match it, and it says which URLs it could not reach.

Contributing

Issues and pull requests are welcome, particularly measurements: a check that misses a real defect, or one that fires on a healthy site, is the most useful thing you can report. Include the command and its output.

A claim without a source will not be merged — that rule is the product, not a preference.

License

MIT — see LICENSE.

Changelog

Changelog

All notable changes to the web-launcher plugin are documented here. The format follows Keep a Changelog, and this project adheres to Semantic Versioning.

Content in this plugin carries verification dates. A release that only re-verifies claims still gets an entry, because "checked on this date" is the product.

[Unreleased]

[0.3.3] - 2026-09-25

Added

  • CI's changelog check now requires a [x.y.z]: link for every released version and an [Unreleased] link that compares from the newest tag. Two releases shipped without their links and [Unreleased] kept comparing from v0.3.0; nothing looked, so nothing noticed.
  • README: what to do when GeoDaddy fails to connect. The first npx start downloads the analyzer binary and can run past Claude Code's 30-second MCP limit (MCP_TIMEOUT raises it), and the package's postinstall ignores a failed download, so the server starts and only analyze_url breaks.

Changed

  • Versions re-resolved on 2026-09-25 against npm and GitHub: satori 0.33.5, @vercel/og 1.0.3, astro-og-canvas 0.13.2, @astrojs/sitemap 3.7.4, wrangler 4.140.0, Lighthouse 13.5.0, codeql-action v4.38.2 (SHA re-resolved), TruffleHog v3.97.9, Syft v1.52.0, CycloneDX spec 1.7.2.
  • pnpm 12 became latest, which is the event 13-dependency-security.md said to re-check on. pnpm/action-setup now supports pnpm 12 and earlier, but only from v6.1.0 — its floating v6 tag still points at v6.0.10 — so the example pins the v6.1.0 SHA with version: 12. pnpm/setup moved to a breaking v3 that installs pnpm 11+ only and runs pnpm install by default. The old "action-setup is for v10 and older" framing is gone.
  • Lighthouse 13.5.0 reshaped the Agentic Browsing category: llms-txt changed group and an ard-schema audit (ai-catalog.json) was added. 11 lists all seven audits.
  • draft-ietf-aipref-vocab-08 added an ai-use category. 06 said AIPREF had no counterpart to Content-Signal's ai-input; it now has a provisional one.

Removed

  • Every indexing and logo timeline. 10 and 12 quoted unsourced ranges that disagreed with each other, while 09 said never to quote a number. 09's rule now holds everywhere: "days to weeks, depending on crawl frequency", and Search Console for the real signal.

Fixed

  • C1 failed every healthy site. Its probe paths are meant not to exist, and since 0.3.0 only a final 200 passed, so a correct 404 printed FAIL. C1 judges redirects: a direct 404 now passes, a redirect ending anywhere but 200 fails, a 5xx fails, and the OK line counts how many probes actually redirected.
  • C3 passed a site with no consolidation at all. Every variant answering 200 printed four OK lines — the split-authority and missing-HTTPS-redirect defects C3 exists to catch. Exactly one variant may now answer 200; the others must 301/308 into it.
  • 09's action-pin grep matched nothing. It was the regex 13 had already replaced for exactly that reason; the sibling was left behind. It now runs 13.11 check 4.
  • The baseline CSP still carried script-src 'unsafe-inline', although 0.3.0's changelog and 08's own note said it had been removed.
  • SKILL.md's always-loaded pitfalls contradicted 08: an unconditional SPA fallback, two field observations 08 had removed as unsourced (purge before retesting, "Bindings=0"), and a Worker redirect where 08 recommends a zone rule. Rewritten to match 08.
  • 08's Worker-redirect variant hardcoded the SPA fallback and its checks expected random paths to answer 200 — the soft 404 0.3.0 removed from the baseline. 11.1 tested www→apex only on a random path, the one probe that passes when a Worker never sees real pages.
  • 09 and 11 pinned every probe to a hardcoded Cloudflare IP, which breaks a platform-agnostic audit of any site not on Cloudflare. The address now comes from DNS.
  • 15's citation check could not see a Disallow. Grepping token names prints User-agent: lines and nothing for a User-agent: * block. It now resolves each token to its governing group. The file also said four of GeoDaddy's six bot checks were training crawlers; it is five.
  • 16 mapped "Blocked by robots.txt" to indexingState: BLOCKED_BY_ROBOTS_TXT, which Google marks "Reserved, no longer in use" (as is verdict PARTIAL). It now uses robotsTxtState and pageFetchState.
  • 13.11 ran yarn outdated, which 13.3 says Yarn Berry does not have, and the 13.3 workflow tag-pinned the third-party actions 13.7 says to SHA-pin.
  • 06 called sitemap and security-txt IANA-registered link relations (they are not), told the reader to ship the empty JWKS placeholder while its own matrix says to skip it, and pointed at 11 for a live-vs-repo diff that lives in 14 C2.
  • 09 proposed Content-Signal and the empty JWKS placeholder as fixes, called a missing Content-Signal a GEO weakness, and counted a scanner score rise as re-validation; 13.11 rated Content-Signal 🟡. 06's matrix and SKILL.md's ⚪ band say they have no known effect. They are intent-only everywhere now.
  • mask-icon was dropped in 01 and 02 but re-added by 03's meta template, 09's patch plan and SKILL.md's scan. It is gone everywhere now; 03 and 02 gained the favicon.ico 01 requires.
  • 02 stated as verified two iOS claims 01 says have no primary source.
  • 05's orphan check compared /docs/x against /x, so every page read as an orphan.
  • 11 cited Lighthouse font-size and tap-target audits that no longer exist, and miscounted the WebMCP audits.
  • 03's humans.txt template carried a real project's stack; 13's examples a real timezone.
  • 01's emoji search used grep -P, which macOS grep rejects.
  • 14: C2's managed-block test printed nothing on success, C5 reported a sitemap index as clean, and C6/C9 missed tags whose attributes came in the other order.
  • 03's llms.txt claim now cites Google's documentation update, and marks the crawler-traffic claim as secondary.
  • SKILL.md said Mode A ran the Mode-B-only live probe and counted 13 validators where 11 lists
    1. Its description now leads with the trigger keywords.

[0.3.2] - 2026-09-08

Fixed

  • Two release blocks in this changelog held the same fixes twice. 0.3.1 carried two ### Fixed headings describing the same four repairs in different words, and 0.3.0 split twenty genuine entries across two ### Fixed lists with a ### Changed between them. The cause was the same in both: separate pull requests each appended to [Unreleased], and the release stamped both without merging them. Merged, with every unique entry kept — including the **/references/local/ ignore-rule entry that appeared in only one of 0.3.1's two blocks and would have been lost by deduplicating on the heading alone. The Workers "deployment finished" claim, which was recorded once under Fixed and again under Changed, is now stated once.

Added

  • CI checks the changelog's structure: no section heading twice inside one version block, only Keep a Changelog section names, an [Unreleased] section that the next change can land in, and one dated heading per version. This file spent two weeks stating the same fixes twice and no check looked; a written convention is not a check, which is the argument this plugin makes about every site it audits.

[0.3.1] - 2026-08-28

Fixed

  • Two more checks passed on a dead origin. 0.3.0 fixed C1, C5, C7's zero-URL case and C9; a sweep of every check against the same six false-pass patterns found C4 (hop_count) reporting OK … 0 hop for an unreachable host — masking exactly the dead-alias defect it exists to catch — and C7 (shell_leak_check) reporting OK no shell leak when the origin never responded at all, because every size is 0 and every code is 000. Both now detect the 000 sentinel first and print ? not checked.
  • 13-dependency-security.md still ran pnpm audit || npm audit. 0.3.0 fixed this in 09-audit-workflow.md and left the sibling instance in the Mode B checklist untouched. Audit tools exit non-zero when they find something, so on a pnpm project with a real CVE the fallback fired and ran npm audit against a lockfile it cannot read. The sweep now detects the one manager the project uses from its lockfile and runs only that, with bun and yarn branches added.
  • The .gitignore rule protecting references/local/ was pinned to a literal path. The sibling repository had the same shape of rule, and a directory rename stopped it matching — silently, with no error — putting maintainer-only files one git add -A away from a public commit. Nothing leaked here, but the rule was one git mv from the same failure. It is now **/references/local/, and CI asserts that nothing under references/local/ or docs/ is tracked. This plugin tells every repo it audits that a written rule is not a check; the rule that keeps its own maintainer notes private is now checked.
  • The @vercel/og row in 07-og-satori.md said 1.0.1 while the prose two lines above said 1.0.2. The table is the block an agent quotes; it now says 1.0.2, published 2026-08-24, which moved its own pin to [email protected]. Verified against the registry on 2026-08-28.
  • A claim added in 0.3.0 carried no date and no source, which is what this skill's own rule 3 forbids: that Workers has no "deployment finished" event. The Workers configuration docs were read on 2026-08-28 and document no such event, but an absence is not a documented denial and a full enumeration of trigger types was not confirmed. The advice is unchanged — a step after wrangler deploy works either way — but the claim behind it is now marked partly verified rather than reading as established fact.

[0.3.0] - 2026-08-28

Fixed

  • C1 passed a direct 404. The 000 no-response branch (the C1 entry below) left the gap underneath it: a path that 404s without ever redirecting matched no branch, so fail stayed 0 and the check printed OK redirect targets resolve to 200. Only an explicit 200 at the end of the chain is a pass now. C5 printed success on a sitemap that never downloaded — zero URLs read is reported as "check did not run", not as a clean site. C7 gained the same guard.
  • The baseline wrangler.jsonc shipped an SPA fallback to every site. not_found_handling: "single-page-application" turns any unknown route on a multi-page site into a 200 serving the homepage — a soft 404 that C1 cannot catch either, because the response genuinely is 200. Now tied to the site shape the scan phase already establishes.
  • 03's meta template contradicted 01 and 10 on icon format, using favicon.svg for apple-touch-icon and Organization.logo where the other two files say, with sources, that both must be raster. Copying the template shipped an apple-touch-icon iOS will not render and a logo Google will not put in the Knowledge Panel.
  • The README promised a POSIX shell and the checks were bash-only. Two blocks used process substitution. Rewritten; all 11 blocks in 14-diagnostic-checks.md and every block in 09 and 11 now pass dash -n as well as bash -n, so the promise is true rather than softened.
  • pnpm audit … || npm audit … ran both scanners. Audit tools exit non-zero when they find something, so the fallback fired on a real vulnerability and ran the second scanner against the wrong lockfile. Replaced with packageManager-then-lockfile detection running exactly one, bun included.
  • 09-audit-workflow.md ended a step with "Commit logically", which is a git mutation the rest of the ski

Releases

  • v0.3.3

    Added

    • CI's changelog check now requires a [x.y.z]: link for every released version and an [Unreleased] link that compares from the newest tag. Two releases shipped without their links and [Unreleased] kept comparing from v0.3.0; nothing looked, so nothing noticed.
    • README: what to do when GeoDaddy fails to connect. The first npx start downloads the analyzer binary and can run past Claude Code's 30-second MCP limit (MCP_TIMEOUT raises it), and the package's postinstall ignores a failed download, so the server starts and only analyze_url breaks.

    Changed

    • Versions re-resolved on 2026-09-25 against npm and GitHub: satori 0.33.5, @vercel/og 1.0.3, astro-og-canvas 0.13.2, @astrojs/sitemap 3.7.4, wrangler 4.140.0, Lighthouse 13.5.0, codeql-action v4.38.2 (SHA re-resolved), TruffleHog v3.97.9, Syft v1.52.0, CycloneDX spec 1.7.2.
    • pnpm 12 became latest, which is the event 13-dependency-security.md said to re-check on. pnpm/action-setup now supports pnpm 12 and earlier, but only from v6.1.0 — its floating v6 tag still points at v6.0.10 — so the example pins the v6.1.0 SHA with version: 12. pnpm/setup moved to a breaking v3 that installs pnpm 11+ only and runs pnpm install by default. The old "action-setup is for v10 and older" framing is gone.
    • Lighthouse 13.5.0 reshaped the Agentic Browsing category: llms-txt changed group and an ard-schema audit (ai-catalog.json) was added. 11 lists all seven audits.
    • draft-ietf-aipref-vocab-08 added an ai-use category. 06 said AIPREF had no counterpart to Content-Signal's ai-input; it now has a provisional one.

    Removed

    • Every indexing and logo timeline. 10 and 12 quoted unsourced ranges that disagreed with each other, while 09 said never to quote a number. 09's rule now holds everywhere: "days to weeks, depending on crawl frequency", and Search Console for the real signal.

    Fixed

    • C1 failed every healthy site. Its probe paths are meant not to exist, and since 0.3.0 only a final 200 passed, so a correct 404 printed FAIL. C1 judges redirects: a direct 404 now passes, a redirect ending anywhere but 200 fails, a 5xx fails, and the OK line counts how many probes actually redirected.
    • C3 passed a site with no consolidation at all. Every variant answering 200 printed four OK lines — the split-authority and missing-HTTPS-redirect defects C3 exists to catch. Exactly one variant may now answer 200; the others must 301/308 into it.
    • 09's action-pin grep matched nothing. It was the regex 13 had already replaced for exactly that reason; the sibling was left behind. It now runs 13.11 check 4.
    • The baseline CSP still carried script-src 'unsafe-inline', although 0.3.0's changelog and 08's own note said it had been removed.
    • SKILL.md's always-loaded pitfalls contradicted 08: an unconditional SPA fallback, two field observations 08 had removed as unsourced (purge before retesting, "Bindings=0"), and a Worker redirect where 08 recommends a zone rule. Rewritten to match 08.
    • 08's Worker-redirect variant hardcoded the SPA fallback and its checks expected random paths to answer 200 — the soft 404 0.3.0 removed from the baseline. 11.1 tested www→apex only on a random path, the one probe that passes when a Worker never sees real pages.
    • 09 and 11 pinned every probe to a hardcoded Cloudflare IP, which breaks a platform-agnostic audit of any site not on Cloudflare. The address now comes from DNS.
    • 15's citation check could not see a Disallow. Grepping token names prints User-agent: lines and nothing for a User-agent: * block. It now resolves each token to its governing group. The file also said four of GeoDaddy's six bot checks were training crawlers; it is five.
    • 16 mapped "Blocked by robots.txt" to indexingState: BLOCKED_BY_ROBOTS_TXT, which Google marks "Reserved, no longer in use" (as is verdict PARTIAL). It now uses robotsTxtState and pageFetchState.
    • 13.11 ran yarn outdated, which 13.3 says Yarn Berry does not have, and the 13.3 workflow tag-pinned the third-party actions 13.7 says to SHA-pin.
    • 06 called sitemap and security-txt IANA-registered link relations (they are not), told the reader to ship the empty JWKS placeholder while its own matrix says to skip it, and pointed at 11 for a live-vs-repo diff that lives in 14 C2.
    • 09 proposed Content-Signal and the empty JWKS placeholder as fixes, called a missing Content-Signal a GEO weakness, and counted a scanner score rise as re-validation; 13.11 rated Content-Signal 🟡. 06's matrix and SKILL.md's ⚪ band say they have no known effect. They are intent-only everywhere now.
    • mask-icon was dropped in 01 and 02 but re-added by 03's meta template, 09's patch plan and SKILL.md's scan. It is gone everywhere now; 03 and 02 gained the favicon.ico 01 requires.
    • 02 stated as verified two iOS claims 01 says have no primary source.
    • 05's orphan check compared /docs/x against /x, so every page read as an orphan.
    • 11 cited Lighthouse font-size and tap-target audits that no longer exist, and miscounted the WebMCP audits.
    • 03's humans.txt template carried a real project's stack; 13's examples a real timezone.
    • 01's emoji search used grep -P, which macOS grep rejects.
    • 14: C2's managed-block test printed nothing on success, C5 reported a sitemap index as clean, and C6/C9 missed tags whose attributes came in the other order.
    • 03's llms.txt claim now cites Google's documentation update, and marks the crawler-traffic claim as secondary.
    • SKILL.md said Mode A ran the Mode-B-only live probe and counted 13 validators where 11 lists
      1. Its description now leads with the trigger keywords.
    Open on GitHub
  • v0.3.2

    Fixed

    • Two release blocks in the changelog held the same fixes twice. 0.3.1 carried two ### Fixed headings describing the same four repairs in different words, and 0.3.0 split twenty genuine entries across two ### Fixed lists with a ### Changed between them. The cause was the same in both: separate pull requests each appended to [Unreleased], and the release stamped both without merging them. Merged, with every unique entry kept — including the **/references/local/ ignore-rule entry that appeared in only one of 0.3.1's two blocks and would have been lost by deduplicating on the heading alone. The Workers "deployment finished" claim, recorded once under Fixed and again under Changed, is now stated once.

    Added

    • CI checks the changelog's structure: no section heading twice inside one version block, only Keep a Changelog section names, an [Unreleased] section that the next change can land in, and one dated heading per version. This file spent two weeks stating the same fixes twice and no check looked; a written convention is not a check, which is the argument this plugin makes about every site it audits.

    No reference file changed in this release — the diagnostic checks and their verification stamps are unchanged from 0.3.1.

    Full changelog: https://github.com/voyvodka/web-launcher/blob/main/CHANGELOG.md

    Open on GitHub
  • v0.3.1

    Follow-ups from a full re-audit. Every item is something 0.3.0 missed.

    Fixed

    • Two more checks passed on a dead origin. 0.3.0 fixed C1, C5 and C9 for this pattern. Sweeping every check against it found two more: C4 (hop_count) reported OK … 0 hop for an unreachable host — masking the dead-alias defect it exists to catch — and C7 (shell_leak_check) reported OK no shell leak when the origin never answered, because every size is then 0 and every code 000. Both now print ? not checked.
    • 13-dependency-security.md still ran pnpm audit || npm audit. 0.3.0 fixed that exact line in 09-audit-workflow.md and left the sibling in the Mode B checklist. Audit tools exit non-zero when they find something, so on a pnpm project with a real CVE the fallback fired and ran npm audit against a lockfile it cannot read.
    • The @vercel/og row in 07-og-satori.md said 1.0.1 while the prose two lines above said 1.0.2. The table is the block an agent quotes.
    • A claim added in 0.3.0 — that Workers has no "deployment finished" event — carried no date and no source, which is what this skill's own rule 3 forbids. It now states what was checked and when, and marks the conclusion unverified: the docs document no such event, but an absence is not a denial.
    Open on GitHub
  • v0.3.0

    Diagnostic correctness. If you run the check suite, upgrade.

    Fixed — checks that reported success on a failing site

    • C1 passed a direct 404. v0.2.0 added the 000 no-response branch and left the gap under it: a path that 404s without redirecting matched no branch, so the loop printed OK redirect targets resolve to 200. Only an explicit 200 at the end of the chain is a pass now.
    • C5 reported a missing sitemap as a healthy one. A sitemap that 404'd, timed out or parsed to nothing produced zero iterations and then printed OK all sitemap URLs return 200. Zero URLs read is now ?, not a pass. C7 gained the same guard.

    Fixed — a deploy baseline that generated soft-404s

    not_found_handling: "single-page-application" sat unconditionally in the wrangler.jsonc every deploy path copies. On a multi-page site that serves the homepage with a 200 for every unknown route — and C1 cannot catch it, because the response really is 200. Now chosen from the site shape the scan phase already establishes.

    Fixed — the POSIX promise

    The README says the checks need a POSIX shell; two blocks used process substitution. Rewritten rather than softening the promise: every bash block in 14, 09, 11 and 08 now passes dash -n as well as bash -n.

    Fixed — pnpm audit || npm audit ran both

    Audit tools exit non-zero when they find something, so the fallback fired on a real vulnerability and ran the second scanner against a lockfile it does not understand. Now detects packageManager then lockfile and runs exactly one, bun included.

    Also

    • 03's meta template used favicon.svg for apple-touch-icon and Organization.logo while 01 and 10 say with sources that both must be raster.
    • "Commit logically" now needs its own approval, alongside deploy, cache purge, sitemap submit and DNS changes — applying a change is not publishing it.
    • Search Console defaults to the webmasters.readonly scope, and says plainly that it is a procedure rather than shipped client code.
    • The checks that follow URLs out of fetched content (<loc>, og:image) now say what that means when the origin is not yours.
    Open on GitHub
  • v0.2.0

    Content corrections found by a full re-audit on 2026-08-28, plus the repository's first CI gate.

    Fixed

    • Two action pins in 13-dependency-security.md could not resolve. The github/codeql-action v4 row gave a SHA absent from that repository entirely, so a workflow copying it failed to find the action rather than running a stale one. pnpm/action-setup v6 was pinned to the annotated tag object instead of its commit. Both came out of the resolution command the file itself recommended, which returns .object.sha without dereferencing annotated tags. The file now gives the one-step form and explains the trap.
    • 06-agent-ready.md had the AIPREF status backwards. It described draft-ietf-aipref-attach as expired and told the reader to wait for it to revive. It revived as -05 on 2026-08-19 and runs to 2027-02-20; vocab moved to -07. Corrected in all three places it appeared. Nothing is known to parse Content-Usage yet, so it stays an intent-only signal.

    Changed

    • .mcp.json pins [email protected]; it previously ran npx -y geodaddy-mcp, so every session executed whatever the registry served as latest.
    • Versions refreshed against the registries on 2026-08-28: satori 0.29.0 → 0.33.4, codeql-action → v4.37.9, TruffleHog → v3.97.1, Syft → v1.51.1, pnpm → 11.24.0. The satori jump spans four minor releases whose notes have not been read, so the CSS-support claims below it are marked not re-verified rather than carried forward silently.

    Added

    • CI that validates the manifest and checks the capability index against references/ in both directions — a row pointing at nothing and a reference nothing routes to are both breakage that manifest validation cannot see.
    • Dependabot for the pinned action SHAs. This plugin recommends the practice; it now follows it.
    Open on GitHub