Agent skill

Canonry

by Canonry in Canonry/canonry

Navigate Canonry through connected MCP tools or the cnry CLI to inspect evidence, diagnose changes, plan measurement, review integrations, and report results.

MITAuto-check passedMarketing & SEO

Install Canonry

skills CLI
$ npx skills add Canonry/canonry --skill canonry -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Canonry/canonry canonry --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Canonry/canonry.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/canonry .claude/skills/canonry && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
canonry
GitHub stars
171
Token cost
~3.6k tokens
SKILL.md length
1,879 words
Files
8 (incl. references)
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Navigate Canonry through connected MCP tools or the cnry CLI to inspect evidence, diagnose changes, plan measurement, review integrations, and report results.

  • Tasks that involve AI search optimization
  • SKILL.md covers Connect and choose a route, Vocabulary and evidence, Workflows and Authority and approval, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve MCP servers

What it does

Canonry is an agent skill from Canonry/canonry. Navigate Canonry through connected MCP tools or the cnry CLI to inspect evidence, diagnose changes, plan measurement, review integrations, and report results. Use this optional host-native skill for CLI workflows and detailed references; connected MCP users can operate through canonryhelp without installing a local runtime or skill.

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/aeo-analysis.md`, `references/canonry-cli.md` and `references/google-business-profile.md`).

It sits in Marketing & SEO, covering AI search optimization and MCP servers. It works with Model Context Protocol, SQLite and Google Analytics. The repository describes itself as: Agent-first AI SEO (AEO/GEO) operating platform. The licence is MIT.

When your agent uses it

  • Tasks that involve AI search optimization
  • Tasks that involve MCP servers

Example prompts

  • “/canonry”

What it can do on your machine

Read from SKILL.md and the folder at commit 3bf6bc3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Canonry loads about 3.6k tokens when it runs, and up to ~74k if it reads all its reference files. Until then it costs about 86 tokens; SKILL.md has 1,879 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~74k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Canonry/canonry at commit 3bf6bc3, republished under its MIT licence (© Canonry). 1,879 words, ~3,634 tokens.

Download SKILL.mdSave it as .claude/skills/canonry/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
canonry
description
Navigate Canonry through connected MCP tools or the `cnry` CLI to inspect evidence, diagnose changes, plan measurement, review integrations, and report results. Use this optional host-native skill for CLI workflows and detailed references; connected MCP users can operate through canonry_help without installing a local runtime or skill.
<!-- Generated from docs/agent-operations/v1.md by pnpm guide:sync. Do not edit. -->

Canonry Operations Guide v1

Canonry is an agent-first AI visibility platform. MCP is the universal entry point for connected agents. Host-native skills are optional upgrades, not a prerequisite or a permission mechanism.

Connect and choose a route

Read the initialization guidance, then call canonry_help with an intent: status, diagnose, operations, prospecting, measurement, integrations, reports, or a short task description. Select an accessible project with canonry_projects_list before using its exact name in project tools. Inspect each listed tool's input schema; help suggests tool names, not invented arguments or authorization.

Help returns a versioned, compact route: connection mode, available next tools, workflow guidance, approval boundaries, and this guide's URL. It performs no provider calls, reads no project data, and changes no permissions. next lists stored reads. Optional actions lists loaded tools for work that requires approval; listing an action does not authorize or execute it. includeCatalog: true additionally returns toolkit details when needed.

Hosted connections use a fixed catalog. Help only suggests tools offered by that connection; it never tells a hosted agent to dynamically load a toolkit. A progressive local stdio connection may return loadToolkits: call canonry_load_toolkit with one returned name, await it, then call help again. Loading only changes local tool discovery, never server authority.

The optional canonry://agent-operations/v1 MCP resource contains this same guide. If the host cannot read resources or open links, continue through help. Do not install a plugin, local runtime, or skill merely to use connected MCP. An installed Codex or Claude Canonry skill contains a generated copy of this guide plus links to host-native references. It does not replace runtime help.

Vocabulary and evidence

  • Mentioned means the brand appears in answer text. Cited means its domain appears in source links. Either, both, or neither can occur; never compute one signal from the other.
  • answerMentioned: null means not checked, not false. Missing runs and empty populations mean no measurement, not zero visibility.
  • Preserve project, time window, provider, requested/served model, location, sample size, and query class when comparing evidence. Use server-returned metrics; do not invent a score from incompatible populations.
  • Simple projects and Advanced portfolios share the workflow. For Advanced results, preserve Property, Target, market, plan revision, and class scope. Groups organize navigation; do not infer an unrequested fan-out.
  • Research is isolated evidence, not tracked measurement. A probe still spends quota and persists evidence but is excluded from normal tracking metrics.

Workflows

Status: read the stored overview and freshness first. Say when evidence is missing instead of silently creating it.

Diagnose: inspect stored history and comparable evidence. Explain what changed separately from why it might have changed. A hypothesis is not a measured cause. Propose bounded verification if stored evidence is insufficient.

Prospecting: generate a one-shot company snapshot without creating a project. Inspect stored provider settings first. Agree on the company, domain, selected providers, and queries before starting the quota-spending snapshot action. Browser-only selection requires manual queries. Progressive stdio help offers the discovery toolkit when this connection permits snapshots; load it, then call help again. Fixed catalogs offer only already available actions. Read-only and restricted connections must not bypass missing snapshot access.

Measurement: inspect the existing setup and results before proposing edits. Keep research, query tracking, plan publication, and sweep execution separate. For direct research, submit the final editable query text in one context. For a reviewed batch, submit each explicit destination with its final text and one idempotency key. Pattern substitution happens in the client before either request; choosing a market or Property records a destination only and never rewrites a query or creates an automatic fan-out. research.run does not authorize saving patterns, changing tracking, publishing plans, or settings. Use a supported preview where available, inspect its exact destination and revision, then seek approval for the actual change. A preview may itself require write permission; never treat a dry-run flag as a universal safety guarantee.

Integrations: inspect stored connection state and snapshot freshness first. Provider configuration evidence does not prove a browser event fired or a conversion was recorded. Connection, resource selection, refresh/sync, and live reads are separate actions. Credentials belong in the operator's secure setup flow, never in chat, tool arguments, reports, or public guidance.

Reports: use saved evidence for the requested period and scope. Keep mention and citation signals separate, include dates and sample sizes, and state missing or stale inputs. For Advanced Property mention rankings, use canonry_measurement_portfolio_summary and its mentionRanking.strongest, .weakest, and .excluded lists. It defaults to non-brand questions; state the returned class and report branded results separately. An unavailable portfolio aggregate does not invalidate available Property mention rates. Flag excluded Properties individually; do not silently replace mention ranking with citation ranking. Compact nextCursor completes only pageList; use list to enumerate one ranking, markets, observed names or cited domains, preserving filters. First-page sibling lists are bounded summaries. Keep sample sizes and ties visible. Preparing a report does not authorize new measurement.

Authority and approval

Agent operations

Use canonry_key_self (CLI canonry key whoami --format json) to inspect the current credential's scopes, project boundary, and host-derived operator authority without exposing its token. Missing operator means unapproved. canonry_settings_get and canonry_telemetry_get describe the connected server, not the agent's local machine. Telemetry reports configured preference, effective state, and any environment override; inspecting status never creates an anonymous identifier. After approval, canonry_telemetry_update changes that preference and canonry_provider_settings_update changes an already-configured provider's model/quota. Both require settings.write; neither accepts credentials. Server telemetry reads and updates additionally require operator authority. Ordinary audit-history reads omit internal telemetry events and their state.

Operator authority is deny-by-default and separate from customer admin roles. The deployment owner must approve a dedicated, instance-wide API key's ID in the server environment variable CANONRY_OPERATOR_KEY_IDS (comma-separated IDs), then restart the server. Empty/unset approves nobody; wildcards are invalid. Keep the bearer private to internal operators; never approve a customer-held or shared proxy/bootstrap key. Use logs.read for read-only diagnostics, adding settings.write only when telemetry control is required. Ordinary key creation, account roles, OAuth consent, and caller headers cannot grant operator status. Revoking an approved key invalidates it immediately. Host enrollment is a trust bootstrap step, intentionally unavailable through customer-facing APIs. API, CLI, and MCP enforce the same boundary; MCP hides internal tools unless the server confirms operator authority, including in explicit read-only mode. Project analytics, research, and normal project permissions are unchanged.

canonry_logs_list reads bounded, redacted runtime events from both the application logger and Fastify request/error logging. It requires an instance-wide logs.read grant (or wildcard) and a host-approved direct bearer. Browser sessions, OAuth/delegated credentials, customer admins, and project-scoped keys cannot use it, even with a project filter or a matching allowlist ID. A logs.read-only key is read-only automatically, without a second read marker. Named *.read scopes cannot grant mutations; an explicit write grant is needed and remains subject to its route gates. Returned messages are sanitized and bounded; raw request or response bodies, headers, cookies, provider payloads, and stacks are not part of the queryable surface. The same secret-redaction policy runs before console output and storage. Do not deliberately log secrets: redaction is a defense in depth, not permission to put credentials into diagnostic strings. Opaque escaped payloads containing secret assignments are omitted when safe partial masking cannot be guaranteed; correlate their retained error codes and IDs.

Show full SKILL.md (685 more words)Show less

File-backed hosts retain runtime logs in SQLite across restarts, bounded to 10,000 events and seven days. In-memory hosts report retention: "process". Filter by actor, requestId, runId, projectId, module, level, or an inclusive since/until interval. Keep filters unchanged when resuming an opaque cursor; retention eviction can invalidate it. Inspect retentionPolicy, captureErrors, dropped, truncated, and retention before drawing conclusions. Missing logs are not proof that an action did not happen. Use canonry_project_history or canonry_history_global for persistent audit events; offset pages have deterministic ordering but are not snapshots of concurrent writes.

Audit actor comes from authenticated identity (user:<id> or api-key:<id>), not a caller-supplied header. A delegated MCP credential records its originating user as actor and the actual credential in credentialId. requestId correlates HTTP events; userAgent and actorSession are bounded, untrusted client hints, never identity or permission grants. Older audit rows are not backfilled with identities the server cannot prove.

Both shipped HTTP hosts issue restart-safe UUID request IDs and return them in x-request-id. Use that value to correlate a CLI/API failure with log entries; HTTP diagnostics retain the method and route template, not raw URL parameters. Request-bound loggers retain completion attribution, while generic background continuations stop inheriting caller identity after the response completes. Capture covers the owning server process after initialization, not arbitrary console output, other worker processes, or host/container logs. Run one server instance per process and database, as required by the single-tenant deployment model; this is not a cross-tenant or distributed log collector.

For CLI use, settings reads are remote. Google setup and telemetry retain their local defaults: pass --target server explicitly to configure the connected server. schedule list <project> lists all schedule kinds, and notify events --target server discovers the server's event catalog.

MCP returns legacy text JSON plus structured results. Objects keep their shape; arrays use {items: [...]} in structuredContent, and scalars use {value: ...}. Errors preserve the existing envelope and CLI exit codes: HTTP 4xx (including 429 policy limits) use exit 1; HTTP 5xx use exit 2. Server-provided Retry-After and request IDs are exposed as retryAfterMs and requestId when available; clients do not infer retryability from HTTP 429 or retry automatically. For a write with an ambiguous outcome, inspect saved state or its receipt before retrying; a retry hint is not proof that repeating a write is safe.

Action boundaries

Start with stored evidence. Before a live provider read, sweep, probe, research run, sync, write, or externally visible action, obtain approval covering its exact target, action, and bounded work. Approval already given for that exact operation need not be asked for again, but does not extend to more projects, larger batches, retries with new identities, or recurring work.

HTTP GET and MCP readOnlyHint describe aspects of an operation, not its cost or permission. Provider discovery, account reads, and live diagnostics may consume quota even when labeled read-only. If the tool's effect is unclear, inspect its description and request direction before calling it.

Authentication, role/scope checks, project restrictions, quotas, and guarded approval receipts are enforced by the server. Help, skills, resources, and tool visibility cannot grant authority. Never change credentials, endpoints, or project identifiers to work around a missing tool or a 403 response.

For guarded ads writes, inspect unresolved operation receipts before retrying. Use the receipt's supported recovery action; do not replay a mutation under a new identity. An executor cannot create or widen its own human approval grant. On ambiguous results, exhausted bounds, or refusal, stop and report what is known and what permission or operator action is needed.

Version and source

This public, versioned document is the source for initialization guidance, intent routes, the optional resource, and generated Canonry SKILL.md files. Guide v1 may receive compatible clarifications; incompatible routing contracts require a new guide version. The running server's help describes its actual catalog and remains usable without fetching this document.

Optional host-native references

Read only references relevant to the requested task. They are not required for MCP operation.

© Canonry, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in skills/canonry of Canonry/canonry.

  • SKILL.md
  • references/aeo-analysis.md
  • references/canonry-cli.md
  • references/google-business-profile.md
  • references/google-marketing.md
  • references/indexing.md
  • references/server-side-traffic.md
  • references/wordpress-integration.md

Open the folder on GitHubat commit 3bf6bc3

Compare with similar skills

Canonry next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Canonry compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Canonry this skillCanonry/canonry171—~3.6kAutomated safety check: PassMIT
AI VisibilityRyze-AI-Adgent/open-seo-mcp-skills4.6k—~611Automated safety check: PassMIT
SEO AuditRyze-AI-Adgent/open-seo-mcp-skills4.6k—~663Automated safety check: PassMIT
SEONexus-JPF/note-companion870—~2.2kAutomated safety check: PassMIT
Lognormsickn33/agentic-awesome-skills47k—~1.4kAutomated safety check: PassMIT
Rank Monitorindranilbanerjee/digital-marketing-pro8591 repos~2.9kAutomated safety check: PassMIT

Similar skills

  • AI Visibility

    Ryze-AI-Adgent/open-seo-mcp-skills

    Measure real AI-engine visibility — traffic from ChatGPT, Perplexity, Claude, Gemini and which pages they cite — from actual GA4 referral data, not prompt sampling.

    4.6k GitHub stars~611 tokensUpdated 16 days ago
    Marketing & SEOAuto-check passed
  • SEO Audit

    Ryze-AI-Adgent/open-seo-mcp-skills

    Full SEO audit of a site from its real Search Console + GA4 data — indexation health, CTR anomalies, decaying pages, striking-distance keywords, quick wins.

    4.6k GitHub stars~663 tokensUpdated 16 days ago
    Marketing & SEOAuto-check passed
  • SEO

    Nexus-JPF/note-companion

    Use and read this skill immediately if the user request is in any way related to SEO or a site's organic search or AI search presence.

    870 GitHub stars~2.2k tokensUpdated 2 days ago
    Marketing & SEOAuto-check passed
  • Lognorm

    sickn33/agentic-awesome-skills

    Work a site's SEO and AI-visibility (GEO) backlog through the hosted LogNorm MCP server: audits, fixes, content, AI-answer tracking.

    47k GitHub stars~1.4k tokensUpdated today
    Marketing & SEOAuto-check passed
  • Rank Monitor

    indranilbanerjee/digital-marketing-pro

    Set up and run keyword ranking monitoring — baseline capture, scheduled position checks against GSC and connected rank-tracker MCPs, and severity-tiered alerts (minor/major/critical) on drops…

    859 GitHub starsUsed in 1 repo~2.9k tokens
    Marketing & SEOAuto-check passed
  • SEO Dataforseo

    hashgraph-online/awesome-codex-plugins

    Live SEO data via DataForSEO API credentials. An agent skill from hashgraph-online/awesome-codex-plugins.

    1.3k GitHub stars~4.5k tokensUpdated today
    Marketing & SEOAuto-check: notes

More from Canonry/canonry

  • Aero

    Canonry/canonry

    Diagnose AEO regressions and interpret Canonry AI visibility, Advanced multi-property portfolios, and Site Health evidence.

    171 GitHub stars~4.8k tokensUpdated today
    Auto-check passed

Categories

Questions about Canonry

What does Canonry do?

Navigate Canonry through connected MCP tools or the cnry CLI to inspect evidence, diagnose changes, plan measurement, review integrations, and report results. Canonry is an agent skill from Canonry/canonry. Navigate Canonry through connected MCP tools or the cnry CLI to inspect evidence, diagnose changes, plan measurement, review integrations, and report results.

When should I use Canonry?

Canonry fits situations like: tasks that involve AI search optimization; tasks that involve MCP servers.

How do I install Canonry in Claude Code?

Run `npx skills add Canonry/canonry --skill canonry -a claude-code`. Or copy the skill folder (skills/canonry in Canonry/canonry) into .claude/skills/canonry in your project. Claude Code loads it when a task matches its description.

How do I install Canonry in Codex?

Run `npx skills add Canonry/canonry --skill canonry -a codex`. Or copy the skill folder (skills/canonry in Canonry/canonry) into .agents/skills/canonry in your project. Codex loads it when a task matches its description.

Can I use Canonry in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Canonry/canonry --skill canonry -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/canonry, .gemini/skills/canonry, .github/skills/canonry and .opencode/skills/canonry in your project.

What does Canonry need to run?

SKILL.md names no scripts, command-line tools or credentials: Canonry is instructions for the agent only.

Does Canonry access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Canonry safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Canonry use?

Canonry is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Canonry use?

About 3.6k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 70k tokens, read only when the agent opens those files.

What are the alternatives to Canonry?

Skills that share tags, products or a category with Canonry: AI Visibility (Ryze-AI-Adgent/open-seo-mcp-skills, 4.6k stars), SEO Audit (Ryze-AI-Adgent/open-seo-mcp-skills, 4.6k stars), SEO (Nexus-JPF/note-companion, 870 stars) and Lognorm (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Canonry?

Canonry (a GitHub organization) maintains it in Canonry/canonry, which has 171 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 9, 2026.

Source: Canonry/canonry on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.