Skip to content
Back to skills

Site Check

ASecurity

Checks a website's pages, links, forms and the speed signals a browser can actually observe, and writes a prioritised fix list to site-check-<site>.md. Never submits a form, never signs in, never claims a measurement it did not take. (localstack)

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 2, 2026
ai-agentsgobashtestingperformance

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 2, 2026

npx -y skills add localoy-ai/localstack --skill site-check --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Site Check?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Site Check
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/localoy-ai-site-check/badge)](https://www.skillsdirectory.com/skills/localoy-ai-site-check)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
# GENERATED from SKILL.md.tmpl — edit the .tmpl, then run scripts/build.sh.
name: site-check
version: 0.1.0
publisher: localoy
capabilities: [files, web, browser]
description: >-
  Checks a website's pages, links, forms and the speed signals a browser can
  actually observe, and writes a prioritised fix list to
  site-check-<site>.md. Never submits a form, never signs in, never claims a
  measurement it did not take. (localstack)
author: localoy
license: MIT
platforms: [linux, macos, windows]
metadata:
  hermes:
    tags: [web, qa, links, forms, performance, localstack]
    related_skills: [site-fix, seo-audit]
allowed-tools:
  - Bash
  - Read
  - Write
  - WebFetch
  - AskUserQuestion
triggers:
  - check my website
  - is my site working
  - find broken links
  - test my site
  - why is my site slow
tags: [web, site-health, broken-links]
---

## When to invoke this skill

Walks a site the way a visitor would and records what is broken or slow:
pages that fail, links that go nowhere, forms that look broken, console
errors, heavy pages. Use when asked to "check my website", "is anything
broken", "why is my site slow". Blip's skill; to fix what it finds, use
`/site-fix`. For titles, metas and rankings, use `/seo-audit`.

## The hard boundary

- **Observed, not assumed.** Every finding names the URL and what was seen —
  the status code, the console message, the byte count, the element. A page
  that would not load is reported as such, never described from memory.
- **Never submits a form.** Submitting sends something to a real business
  inbox or system. Forms are checked by looking: fields present, labels,
  required markers, the action target, errors shown when the page loads.
  Testing a submission is the person's call, per form, and only on a test
  or staging copy they name.
- **No signing in.** Pages behind a login are listed as `not checked —
  login required`. Never type credentials, create an account or solve a
  CAPTCHA.
- **Speed is signals, not a score.** Report what the browser measured on
  this computer, this once: load timing from the page's own performance
  entries, page weight, request count, the largest images and scripts.
  Never a "performance score", never a claim about other visitors.
- **Gentle.** At most 30 pages, one at a time, no load testing.

## What you need first

- **The site URL** (and staging, if the person wants that checked instead).
- **The pages that matter most** — checkout, booking, contact. Default: the
  homepage's navigation.

Ask for what is missing in a SINGLE message, then wait. **Earlier runs:** if
`site-check-<site>.md` exists, say when it was last written; this run
replaces it and reports which earlier findings are now fixed.

## Procedure

**1. Scope.** Open the homepage in the browser; read `sitemap.xml` if there
is one. Build the page list (at most 30): the pages the person named, the
main navigation, key flows. Say how the list was built. `<site>` slug: host,
lowercase, dots as hyphens (`acme-com`).

Scratch for this run lives in `.localstack/work/{date}-{slug}/` — hidden, one directory per run, so a new run never clobbers an earlier one and the folder's top level stays the standard files. Scratch is disposable; old run directories may be deleted freely.

**2. Per page, in the browser:** HTTP status and redirects; console errors
and failed requests; broken images; mobile width (375px) — content cut off
or overlapping, with a screenshot into scratch; performance entries
(`navigation` timing, transfer sizes, request count) read from the page.

**3. Links.** Collect every internal link and each distinct external link;
check each one's status once. Record broken (4xx/5xx), redirect chains, and
links to `http://` on an `https://` site.

**4. Forms.** For each form: fields, labels, required markers, where it
submits (same site? `https`?), visible errors on load. Do not submit.

**5. Prioritise.**
- **Fix now** — a key page or flow broken: 5xx/4xx on a named page, a
  checkout or contact form that cannot work as built, console errors that
  stop the page.
- **Fix soon** — broken links, broken images, mobile layout breaks, very
  heavy pages (name the file and its size).
- **Later** — redirect chains, mixed content warnings, minor console noise.

**6. Write `site-check-<site>.md`** at the top of the working folder:
`Updated: YYYY-MM-DD`, pages checked / failed / not checked (and why), the
fix list by priority (each: URL, what was seen, evidence — screenshot path
or quoted message), then per-page notes, then "fixed since last check" on a
rerun.

**Standard files.** This folder is kept in files any agent already reads. Update them in place; never scatter output into new folders.
- **AGENTS.md** — create it if missing. localstack owns only the block between `<!-- localstack:start -->` and `<!-- localstack:end -->`; rewrite that block, never anything outside it. The block says what this folder is for, the rules (drafts only; nothing is sent without the user's explicit yes, one message at a time; no invented facts), a map of the files below, and one line per topic (its PLAN, its lead count, the next unticked step) and per report (its file and date).
- **CHANGELOG.md** — create it if missing (`# Changelog`). Add one bullet for this run under today's `## YYYY-MM-DD` heading, newest date first: the skill, the topic, and the counts or outcome (e.g. `- lead-search austin-dentists: 18 found, 3 skipped as already contacted`).
- **TODOS.md** — create it if missing (`# TODOs`). Add each open next action as `- [ ] <action> (<topic>)`; tick items this run finished; never delete lines.
- **DESIGN.md** — decisions meant to last (positioning, tone, channels to use or avoid). Read it before writing anything a person will see; add to it only when the user states or approves a decision.

For this step: the CHANGELOG line gives pages checked and fix-now / soon /
later counts. Every "fix now" item → a TODO (`- [ ] <fix> — <URL>
(site-check <site>)`).

**7. Report.** The fix-now items first, then counts. Offer `/site-fix` for
the top item.

**Completion status.** End the chat report with one of:
- **DONE** — completed, with the evidence named (files written, counts, URLs).
- **DONE_WITH_CONCERNS** — completed, and list each concern.
- **BLOCKED** — cannot proceed; say what blocked it and what was tried.
- **NEEDS_CONTEXT** — missing information; say exactly what is needed.

## Quality bar

- Every finding opens to a URL and an observation someone else can repeat.
- Zero forms submitted, zero logins, zero invented scores.
- A 12-page check is reported as 12 pages, never as "the site".

Files in this skill

  • SKILL.md6.5 KB
  • SKILL.md.tmpl4.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…