Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Gingiris-1031/gingiris-skills --skill gr-blog-postgit clone --depth 1 https://github.com/Gingiris-1031/gingiris-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/gingiris-1031/gingiris-skills/gr-blog-post)<a href="https://agentmods.dev/skills/gingiris-1031/gingiris-skills/gr-blog-post"><img src="https://agentmods.dev/badge/skills/gingiris-1031/gingiris-skills/gr-blog-post/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/gingiris-1031/gingiris-skills/gr-blog-post"><img src="https://agentmods.dev/badge/skills/gingiris-1031/gingiris-skills/gr-blog-post.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 5 findings, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Privilege Escalation · line 110 Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.Fix: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths.
- high Privilege Escalation · line 111 Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.Fix: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths.
- high Privilege Escalation · line 187 Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.Fix: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths.
- medium Data Exfiltration · line 115 Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.Fix: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted.
- medium Data Exfiltration · line 118 Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.Fix: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00160 | $0.03763 |
| Opus 5 | $0.00080 | $0.01881 |
| Sonnet 5 | $0.00032 | $0.00753 |
| Haiku 4.5 | $0.00016 | $0.00376 |
Grade A, and why
gr-blog-post scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -s -X PUT \ How it starts
The opening of the file, as written. The whole thing — 277 lines — stays where its author put it; the contents beside it link to each section on GitHub.
⚠️ 2C 产品的写作调整
本 skill 默认 dev/B2B 读者。写 2C 教育/医疗/金融(YMYL) 内容时:
- E-E-A-T 加重:需可验证作者/审核资质 + 方法论透明页,不能只靠"团队"署名(Google:Trust 是 E-E-A-T 核心)。
- 选题双轨:红利词(政策/改革/新版)+ 长尾高转化词(题型/场景/分数级)。
- Key Stats 表格的数字必须有权威来源、前后一致——YMYL 品类不可编造,否则排名修复极难。
- 分发渠道换成 2C 社区/短视频(小红书/Reddit/TikTok/Naver 카페),而非 dev blog。
完整 2C 渠道数据库 + 公开来源见 → gingiris-seo-geo/references/2c-adaptation.md
gr-blog-post — Jekyll 博客发布
产出的文章必须符合
Iris 文风 5 要素(详见 references/writing-voice-iris.md)
- 时间锚定开场 —— 不说"SEO 很重要",说"2026-04-10,凌晨 3 点,后台流量归零"
- 括号旁白 —— 正文一句,括号里挤私货("...—— 别问怎么知道的")
- em-dash 转折 —— 不用"但是",用
—— - Key Stats 表格 —— 文章开头或 H2 下第一屏放一个硬数据表,3-5 行
- GEO 直接答案段落 —— 文章顶部一段 30-50 字直接回答主问题,方便 AI 爬虫抽取
技术 frontmatter 模板
---
layout: post
title: "主关键词前置,副标题用冒号:不超过 60 字"
date: 2026-04-15 14:30:00 +0800
categories: [seo, growth]
tags: [...]
canonical_url: https://gingiris.tools/blog/2026/04/15/slug/
hreflang_ja: /blog/2026/04/15/slug-ja/
hreflang_ko: /blog/2026/04/15/slug-ko/
post_description: "150-160 字 meta description,含主关键词"
faq:
- q: "直接问句"
a: "30-50 字硬答案"
---
发布流程
1. 选题
- 读
gr-seo-patrol输出,找"top 30 但没 top 10"的关键词 - 或读
gr-competitor,找对手新打法 - ❌ 不做重复主题(先
site:查站内是否已有)
2. 写初稿
- 时间锚定开场(当前日期 + 具体场景)
- 第一屏:GEO 直接答案段(30-50 字)+ Key Stats 表(硬数据)
- H2 结构:问题 → 框架 → 案例 → 陷阱 → 下一步
- 每个 H2 下 200-400 字,不超过 600 字
3. 内链
- 向前:链接 2-3 篇已发布的同主题文章(用主关键词作 anchor)
- 向后:站内 index / hub 页
- 权重传导:从流量最大的 3 篇文章加内链到新文
4. FAQ Schema
- 3-5 个问答
- 问句必须是用户真实搜索句(从 GSC / People also ask 抓)
- 答案硬、短、可引用
5. Canonical 策略
- 默认 self-canonical
- 如果是同主题系列的分篇 → canonical 指向 master
- ja/ko 翻译版 → 自身 canonical + hreflang 互指
6. 多语言同步
- 用
scripts/sync-i18n.py(roadmap)从英文自动产日韩草稿 - 人工过一遍(机翻硬伤 + 文化适配)
- 日韩版本独立 slug,不复用英文 slug
7. 发布(可执行清单)
目标 repo:Gingiris-1031/growth-tools(真站 gingiris.tools,Vercel 部署 origin/main,写入后 ~50-90s 自动构建)
⚠️ 前置:先过 Gingiris-1031 GitHub 安全规则(memory gingiris_1031_safety_rules.md,P0):
- 提交身份 =
Iris Wei <[email protected]>(不是机器名/本机 hostname) - 单行 commit message:
post: {slug} ({lang})——无 Claude trailer、无多段正文 - 不 burst:能合并就合并成 1 个 commit;>10 commits/小时 = 停下重排
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 277 lines · 160 tokens per session scan A f3c8969b2b5d
gr-blog-post is a skill published in the GitHub repository Gingiris-1031/gingiris-skills (79 stars, last pushed 4d ago), licensed MIT. It adds 160 tokens to every session and 3,763 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
localization
When the user wants to localize their App Store listing for international markets. Also use when the user mentions "localization", "translate my app", "international markets", "expand to new countries", "localize metadata", or "which countries should I target". For keyword research in specific markets, see…
ios-marketing-capture
Use when the user wants to automate capture of marketing screenshots for a SwiftUI iOS app across multiple locales, devices, or appearances. Covers full-screen shots, isolated element renders (carousel cards, widgets), and reproducible output naming. Triggers on marketing screenshots, locale screenshots, widget…
synthesis-explore
Synthesis EXPLORE stage for the Diffmode growth-tactics pipeline (fuses the blind-combination draw + emergent-mechanism derivation — formerly two separate synthesis steps — into ONE structural-check-only stage). Reads the per-run growth-factors.json (LIGHT vector DB) + synthesis-constraints.json + founder-input +…
growth-factors-mining
Builds a per-run LIGHT growth-vector database for the Diffmode growth-tactics pipeline by mining public growth case studies fresh, every run, and distilling each into atomic "growth factors" (transferable mechanisms). Clean-room — NEVER reads the proprietary tacticsDB. Outputs growth-factors.json (20-40 vectors spread…
diagnostics-intake
Fast founder-input capture for the Diffmode growth-tactics pipeline (the diagnostics stage). Produces WS/01-diagnostics/founder-input.md in the exact schema the enrichment + synthesis stages read. Two modes — (A) URL mode researches a product's website (homepage/pricing/about) plus a web-research pass to prefill the…
lite-constraints
Generates synthesis-constraints.json for the Diffmode growth-tactics pipeline by reasoning in-context over the per-run growth-factors.json (LIGHT vector DB) + founder context — the clean-room, no-Python replacement for the proprietary Python constraints generator. Emits the white-space pairs, mandatory…