Skip to content
Back to skills

Discoverability All

ASecurity

Use when a public site should be found and shared correctly, or when titles, descriptions, canonicals, robots.txt, sitemap.xml, social previews, favicon, and indexing directives need one coordinated review. It runs one shared sweep, then routes only to the specialists whose findings need work. Do not use it as a ranking promise, for a private or intentionally unindexed product beyond confirming it is consistently noindex, or for a single-file fix a specialist already owns.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 1, 2026
ai-agentsgobashnodegitsecuritydocumentation

Works with

  • cli

Security analysis

A100/100

Pro scans all 8 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add moh-obaida/ReadyVibe-Skills --skill discoverability-all --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Discoverability All?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Discoverability All
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/moh-obaida-discoverability-all/badge)](https://www.skillsdirectory.com/skills/moh-obaida-discoverability-all)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: discoverability-all
description: "Use when a public site should be found and shared correctly, or when titles, descriptions, canonicals, robots.txt, sitemap.xml, social previews, favicon, and indexing directives need one coordinated review. It runs one shared sweep, then routes only to the specialists whose findings need work. Do not use it as a ranking promise, for a private or intentionally unindexed product beyond confirming it is consistently noindex, or for a single-file fix a specialist already owns."
license: Apache-2.0
metadata:
  kind: bundle
  launch-checks: "9-18"
  helpers: "inspect-metadata,check-links"
  companions: "seo-readiness,social-sharing,launch-identity,deployment-cleanup,search-console-readiness,structured-data,multilingual-readiness,link-integrity"
---

# discoverability-all

Owns launch family B (checks 9–18): titles, descriptions, canonicals, robots.txt, sitemap.xml, social metadata, favicon/icons, indexing sanity, staging/localhost references, and public URL consistency.

The signals in this family **contradict each other far more often than they are missing**: a localhost canonical on a page the sitemap advertises, a `noindex` page listed in the sitemap, robots blocking what the sitemap lists, a staging host in an Open Graph URL. Existence checks miss all of that. This skill reviews the relationships once, then hands specialists a shared picture so none of them re-crawls the site.

## Activate when

- The site is public and should be discoverable or shareable, or a launch/rebrand/domain move is near.
- `launch-all` routes here.
- Not when the product is private or intentionally unindexed. In that case confirm it is *consistently* noindex (meta or header, no sitemap, robots not advertising private paths) and stop.

## Working alone

This skill is self-contained. Its **companions** (declared in its metadata) are skills whose method it may need to do its own promised work. Use of a companion can be conditional: declaring one does not mean running it. When a companion's lane applies, use the skill if it is installed; if not, follow its short entry in [references/companion-methods.md](references/companion-methods.md) and say in your report which lanes ran inline at reduced depth. Never skip an applicable lane silently. The lanes this bundle can activate are companions because it promises to run them when they apply: consider them all, activate only the ones that fit. Skills mentioned here only for escalation, referral, documentation, or optional deeper follow-up are not dependencies: report the hand-off and finish honestly.

Companions: `seo-readiness`, `social-sharing`, `launch-identity`, `deployment-cleanup`, `search-console-readiness`, `structured-data`, `multilingual-readiness`, `link-integrity`.

## Route

1. **Intent and host.** Establish: should this be indexed? What is the production origin (scheme + host, `www` or not)? Which routes are public, which are private (account, dashboard, admin, checkout, preview)? Read `.readyvibe/context.md`, deployment config, and env templates. If the production URL is unknown, ask once; otherwise use the declared one.
2. **Shared sweep.** Run once and reuse the output (paths are relative to this skill's folder; add `--render` for client-rendered apps):

   ```bash
   node scripts/inspect-metadata.mjs --url <site> --render --private-path /dashboard
   node scripts/check-links.mjs      --url <site> --render
   ```

   Serve a build locally if needed. Without a server, use `--dir <build output>` and mark server-dependent items UNKNOWN.
3. **Select specialists** from the findings, not the table:

| Findings show | Specialist |
|---|---|
| titles, descriptions, canonicals, robots, sitemap, noindex, URL agreement (9–13, 16, 18) | `seo-readiness` |
| missing/incorrect Open Graph or Twitter tags, share image (14) | `social-sharing` |
| starter favicon, missing icons, product-name mismatch in titles (15) | `launch-identity` |
| localhost/staging/preview hosts anywhere shipped (17) | `deployment-cleanup` |
| the owner wants Search Console/Bing verification steps | `search-console-readiness` |
| a real article, product, organization, or FAQ page and JSON-LD exists or would help | `structured-data` |
| more than one language | `multilingual-readiness` (hreflang, per-language canonicals) |
| broken sitemap or canonical targets | `link-integrity` |

Skip `structured-data` and `search-console-readiness` unless there is a concrete reason. Do not add JSON-LD to a page whose content is not what the schema claims.

## Evidence discipline

Label each claim OBSERVED, SOURCE-INDICATED, DECLARED, INFERRED, UNKNOWN, or REVIEW REQUIRED. UNKNOWN is never a pass and never a failure.

- A sitemap that exists is not a sitemap that is safe and correct. Correctness means: canonical, public, live, non-redirecting, not blocked, not noindex.
- Source with a canonical tag is not proof of the *rendered* canonical (a framework may override it). Read rendered HTML.
- Indexing intent is a fact about the owner's plan: DECLARED or asked, never guessed from the framework.
- Never claim a page "will be indexed" or "will rank". Indexing needs search-engine data.

## May change

Metadata tags and site config that generate them, `robots.txt`, `sitemap.xml` (or its generator), favicon/icon files and links, canonical values (only once the production origin is known). Specialists define their own limits.

## Must not claim

"SEO-optimized", "will rank", "will be indexed", "Google-approved", or a score. Report agreements and contradictions found, and fixes verified.

## Verify

Re-run the sweep after changes. Success means the *relationships* hold: every sitemap URL is canonical, public, returns 200, is not noindex and not blocked; every canonical target resolves; the production host is the same everywhere; no localhost/staging strings remain. For a deployed site, spot-check the live URL, not just local output.

## Escalate

- Production origin unknown or about to change: ask before writing any absolute URL.
- A private route that is *reachable* (not just listed) is a security finding: hand to `web-security`.
- Multi-domain, multi-language, or migration setups with redirects: REVIEW REQUIRED for the redirect map.

## No change is valid when

The site is intentionally private and consistently noindex; or a single-page site legitimately has no sitemap; or the findings are explained by context (a `noindex` on `/dashboard` is correct). Do not add a sitemap or structured data just to satisfy a checklist.

Files in this skill

  • SKILL.md6.4 KB
  • references/companion-methods.md3.3 KB
  • scripts/check-links.mjs14.4 KB
  • scripts/inspect-metadata.mjs23.9 KB
  • scripts/lib/browser.mjs3.3 KB
  • scripts/lib/html.mjs5.8 KB
  • scripts/lib/pages.mjs11.3 KB
  • scripts/lib/report.mjs3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…