Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add JakeLabate/Claude-SEO-Skills --skill mixed-content-auditgit clone --depth 1 https://github.com/JakeLabate/Claude-SEO-SkillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jakelabate/claude-seo-skills/mixed-content-audit)<a href="https://agentmods.dev/skills/jakelabate/claude-seo-skills/mixed-content-audit"><img src="https://agentmods.dev/badge/skills/jakelabate/claude-seo-skills/mixed-content-audit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/jakelabate/claude-seo-skills/mixed-content-audit"><img src="https://agentmods.dev/badge/skills/jakelabate/claude-seo-skills/mixed-content-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00123 | $0.01187 |
| Opus 5 | $0.00062 | $0.00593 |
| Sonnet 5 | $0.00025 | $0.00237 |
| Haiku 4.5 | $0.00012 | $0.00119 |
Grade A, and why
mixed-content-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 109 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Mixed Content / HTTPS Audit
Audit an HTTPS site for insecure (http://) resources and produce an actionable
report. Mixed content breaks pages and strips the padlock; this skill finds every
instance and groups it by root cause.
When to use this skill
Use this skill when the user asks to:
- Audit or fix mixed content / the browser "Not secure" warning
- Find
http://scripts, styles, iframes, images, or media onhttps://pages - Verify an HTTPS migration is complete
- Find insecure form actions
Inputs to collect
- Site URL or URL list — a live
https://site root to crawl (auto-seeds from/sitemap.xml), or a text file with--url-list. - Scope — pages to crawl (default 500,
--max-pages).
Workflow
Step 1: Crawl and inventory subresources
Use scripts/extract_resources.py:
python3 scripts/extract_resources.py https://example.com --max-pages 500 --output resource_inventory.json
# already crawled once (e.g. in a full SEO audit)? skip the crawl and reuse the shared cache:
# python3 scripts/fetch_pages.py https://example.com --output page_cache.json
# python3 scripts/extract_resources.py --from-cache page_cache.json --output resource_inventory.json
For every page it records each subresource (scripts, stylesheets, images, iframes, media, embeds, form actions) with its tag, attribute, resolved URL, and scheme.
Step 2: Run the audit checks
python3 scripts/audit_resources.py resource_inventory.json --output audit_report.json
Step 3: Evaluate the audit checks
Evaluate each check in references/audit-checks.md. Core checks:
| Check | Severity |
|---|---|
| Active mixed content (script/style/iframe/object over http) | High |
| Insecure form action (http) | High |
| Passive mixed content (img/audio/video over http) | Medium |
Protocol-relative (//) resource |
Low |
| Page served over http | Info |
Step 4: Produce the report
Write a report following references/report-template.md: summary by severity,
active mixed content and insecure forms first, then passive, grouped by the host
serving the insecure resource, and a prioritized action list.
What ships with it
7 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 109 lines · 123 tokens per session scan A 482952bd2ba9
mixed-content-audit is a skill published in the GitHub repository JakeLabate/Claude-SEO-Skills (2 stars, last pushed 2mo ago), licensed MIT. It adds 123 tokens to every session and 1,187 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
seo-audit
A checklist-based SEO review for a website. SEO, or search engine optimization, is the work of improving a site so search engines can understand and rank it.
fire-your-seo-agency
A procedure for improving how a website appears in search engines and how AI answer systems find and cite it. It covers search, answer-engine, generative-AI, and Naver visibility.
geo-loop
Run one bounded eGEOagents loop iteration over a workspace domain - read the charter and fresh collector data, do ONE unit of work, write substrate artifacts, append one Timeline entry and one LOG line. Use for loop mode, /geo:loop, scheduled GEO runs, or continuous monitoring.
content-scoring
Score content against the 10 GEO criteria with evidence and prioritized fixes. Use when users ask to score, rate, evaluate, or estimate ranking strength.
competitive-analysis
Analyze AI-search competitors for a query and recommend ranking strategy. Use when users ask competitor analysis, who ranks, or competitive landscape.
validation-doctor
Check Brave Search and Chrome DevTools MCP availability and provide exact setup snippets. Use when validation dependencies are missing or uncertain.