Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add powehi-eu/google-suite-seo-mcp --skill google-credentialsgit clone --depth 1 https://github.com/powehi-eu/google-suite-seo-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/powehi-eu/google-suite-seo-mcp/google-credentials)<a href="https://agentmods.dev/skills/powehi-eu/google-suite-seo-mcp/google-credentials"><img src="https://agentmods.dev/badge/skills/powehi-eu/google-suite-seo-mcp/google-credentials/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/powehi-eu/google-suite-seo-mcp/google-credentials"><img src="https://agentmods.dev/badge/skills/powehi-eu/google-suite-seo-mcp/google-credentials.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00039 | $0.00264 |
| Opus 5 | $0.00019 | $0.00132 |
| Sonnet 5 | $0.00008 | $0.00053 |
| Haiku 4.5 | $0.00004 | $0.00026 |
Grade A, and why
google-credentials scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Configure Google credentials
On Windows, use the bundled PowerShell setup wizard:
& "<plugin-root>\scripts\configure-google.ps1"
The wizard collects only local file paths and the non-secret Google Cloud project ID. It copies the JSON credentials to %USERPROFILE%\.codex\secrets\google\, updates the local MCP configuration, and never prints credential contents.
On macOS/Linux, use ./scripts/install-gsc.sh and ./scripts/install-ga4.sh, then export the three variables documented in docs/INSTALLATION.md. Credentials belong under $HOME/.codex/secrets/google/.
After it completes:
- Run
check-auth.ps1and report only structural success/failure. - Ask the user to restart Codex so MCP processes reload the environment.
- Never request or echo private keys, client secrets, refresh tokens, or JSON contents in chat.
If the user does not yet have the JSON files, provide the links in docs/GOOGLE_AUTH.md and stop before collecting secrets.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 25 lines · 39 tokens per session scan A 1e05d1182161
google-credentials is a skill published in the GitHub repository powehi-eu/google-suite-seo-mcp (5 stars, last pushed 1mo ago), licensed MIT. It adds 39 tokens to every session and 264 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
filter-structures
The correct shape for dimensionfilter in getga4data. Wrong structure returns an "Invalid dimensionfilter" error. Use these templates.
traffic-diagnosis
Systematically diagnose why traffic changed — spike, drop, or shift in mix. Follow these steps in order. Each step narrows the hypothesis.
ai-referral-analysis
Measure traffic arriving from AI tools — ChatGPT, Claude, Perplexity, Gemini, Copilot, and others — and understand how it behaves compared to other channels.
attribution-scope
GA4 has three distinct attribution scopes. Using the wrong scope gives misleading results. Choose based on the question you are answering.
bot-traffic-detection
Identify and exclude bot, scraper, and spam sessions from GA4 data.
content-performance
Identify top-performing pages, find underperforming content, and understand engagement patterns across your site.