Agent skill

Phase 7 SEO Security

by ww-w-ai in ww-w-ai/bkit-claude-code

Enhance SEO (meta tags, semantic HTML) and security (vulnerability checks, hardening).

Apache-2.0Auto-check passedSecurity

Install Phase 7 SEO Security

skills CLI
$ npx skills add ww-w-ai/bkit-claude-code --skill phase-7-seo-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ww-w-ai/bkit-claude-code phase-7-seo-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ww-w-ai/bkit-claude-code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/phase-7-seo-security .claude/skills/phase-7-seo-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
phase-7-seo-security
GitHub stars
601
Token cost
~2.3k tokens
SKILL.md length
328 words
Files
1
Skills in repo
44
Repo updated
First seen
Licence
Apache-2.0

At a glance

Enhance SEO (meta tags, semantic HTML) and security (vulnerability checks, hardening).

  • Works in 3 steps: SEO Optimization: Meta tags, structured… → Performance Optimization: Core Web… → Security Enhancement: Authentication,…
  • Tasks that involve On-page SEO
  • SKILL.md covers Purpose, What to Do in This Phase, Deliverables and PDCA Application, plus 8 more sections
  • Needs AUTH_SECRET

What it does

Phase 7 SEO Security is an agent skill from ww-w-ai/bkit-claude-code. Enhance SEO (meta tags, semantic HTML) and security (vulnerability checks, hardening). Triggers: SEO, security, meta tags, vulnerability default: bkit:code-analyzer security: bkit:security-architect

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering On-page SEO and Web application vulnerabilities. The repository describes itself as: bkit Vibecoding Kit - PDCA methodology + Claude Code mastery for AI-native development. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve On-page SEO
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/phase-7-seo-security”

Requirements

  • A credential in AUTH_SECRET
  • Pre-approved tools (allowed-tools): Read, Edit, Glob, Grep, WebSearch

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. SEO Optimization: Meta tags, structured data, sitemap
  2. Performance Optimization: Core Web Vitals improvement
  3. Security Enhancement: Authentication, authorization, vulnerability defense

What it can do on your machine

Read from SKILL.md and the folder at commit 85b4913. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Edit
    • Glob
    • Grep
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and javascript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AUTH_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Phase 7 SEO Security loads about 2.3k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 328 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ww-w-ai/bkit-claude-code at commit 85b4913, republished under its Apache-2.0 licence (© ww-w-ai). 328 words, ~2,295 tokens.

Download SKILL.mdSave it as .claude/skills/phase-7-seo-security/SKILL.md (or your agent's skills folder).
name
phase-7-seo-security
description
Enhance SEO (meta tags, semantic HTML) and security (vulnerability checks, hardening). Triggers: SEO, security, meta tags, vulnerability default: bkit:code-analyzer security: bkit:security-architect
allowed-tools
Read, Edit, Glob, Grep, WebSearch
classification
capability
classification-reason
Pattern guidance may overlap with model's built-in knowledge as it improves
deprecation-risk
medium
effort
medium
user-invocable
false
next-skill
phase-8-review
pdca-phase
do
task-template
[Phase-7] {feature}

Phase 7: SEO/Security

Search optimization and security enhancement

Purpose

Make the application discoverable through search and defend against security vulnerabilities.

What to Do in This Phase

  1. SEO Optimization: Meta tags, structured data, sitemap
  2. Performance Optimization: Core Web Vitals improvement
  3. Security Enhancement: Authentication, authorization, vulnerability defense

Deliverables

docs/02-design/
├── seo-spec.md             # SEO specification
└── security-spec.md        # Security specification

src/
├── middleware/             # Security middleware
└── components/
    └── seo/                # SEO components

PDCA Application

  • Plan: Define SEO/security requirements
  • Design: Meta tags, security policy design
  • Do: SEO/security implementation
  • Check: Inspection and verification
  • Act: Improve and proceed to Phase 8

Level-wise Application

LevelApplication Method
StarterSEO only (minimal security)
DynamicSEO + basic security
EnterpriseSEO + advanced security

SEO Checklist

Basic
  • Per-page title, description
  • Open Graph meta tags
  • Canonical URL
  • sitemap.xml
  • robots.txt
Structured Data
  • JSON-LD schema
  • Breadcrumb
  • Product/Review schema (if applicable)
Performance
  • Image optimization (next/image)
  • Font optimization
  • Code splitting

Security Checklist

Authentication/Authorization
  • Secure session management
  • CSRF protection
  • Proper permission checks
Data Protection
  • Input validation
  • SQL injection defense
  • XSS defense
Communication Security
  • HTTPS enforcement
  • Security header configuration
  • CORS policy

Security Architecture (Cross-Phase Connection)

Security Layer Structure
┌─────────────────────────────────────────────────────────────┐
│                     Client (Browser)                         │
├─────────────────────────────────────────────────────────────┤
│   Phase 6: UI Security                                       │
│   - XSS defense (input escaping)                            │
│   - CSRF token inclusion                                     │
│   - No sensitive info storage on client                      │
├─────────────────────────────────────────────────────────────┤
│   Phase 4/6: API Communication Security                      │
│   - HTTPS enforcement                                        │
│   - Authorization header (Bearer Token)                      │
│   - Content-Type validation                                  │
├─────────────────────────────────────────────────────────────┤
│   Phase 4: API Server Security                               │
│   - Input validation                                         │
│   - Rate Limiting                                            │
│   - Minimal error messages (prevent sensitive info exposure) │
├─────────────────────────────────────────────────────────────┤
│   Phase 2/9: Environment Variable Security                   │
│   - Secrets management                                       │
│   - Environment separation                                   │
│   - Client-exposed variable distinction                      │
└─────────────────────────────────────────────────────────────┘
Security Responsibilities by Phase
PhaseSecurity ResponsibilityVerification Items
Phase 2Environment variable conventionNEXT_PUBLIC_* distinction, Secrets list
Phase 4API security designAuth method, error codes, input validation
Phase 6Client securityXSS defense, token management, sensitive info
Phase 7Security implementation/inspectionFull security checklist
Phase 9Deployment securitySecrets injection, HTTPS, security headers

Client Security (Phase 6 Connection)

XSS Defense Principles
⚠️ XSS (Cross-Site Scripting) Defense

1. Never use innerHTML directly
2. Always sanitize user input when rendering as HTML
3. Leverage React's automatic escaping
4. Use DOMPurify library when needed
No Sensitive Information Storage
typescript
// ❌ Forbidden: Sensitive info in localStorage
localStorage.setItem('password', password);
localStorage.setItem('creditCard', cardNumber);

// ✅ Allowed: Store only tokens (httpOnly cookies recommended)
localStorage.setItem('auth_token', token);

// ✅ More secure: httpOnly cookie (set by server)
// Set-Cookie: token=xxx; HttpOnly; Secure; SameSite=Strict
CSRF Defense
typescript
// Include CSRF token in API client
// lib/api/client.ts
private async request<T>(endpoint: string, config: RequestConfig = {}) {
  const headers = new Headers(config.headers);

  // Add CSRF token
  const csrfToken = this.getCsrfToken();
  if (csrfToken) {
    headers.set('X-CSRF-Token', csrfToken);
  }
  // ...
}

API Security (Phase 4 Connection)

Input Validation (Server-side)
typescript
// All input must be validated on the server
import { z } from 'zod';

const CreateUserSchema = z.object({
  email: z.string().email(),
  password: z.string().min(8).max(100),
  name: z.string().min(1).max(50),
});

// Usage in API Route
export async function POST(req: Request) {
  const body = await req.json();

  const result = CreateUserSchema.safeParse(body);
  if (!result.success) {
    return Response.json({
      error: {
        code: 'VALIDATION_ERROR',
        message: 'Input is invalid.',
        details: result.error.flatten().fieldErrors,
      }
    }, { status: 400 });
  }

  const { email, password, name } = result.data;
}
Error Message Security
typescript
// ❌ Dangerous: Detailed error info exposure
{
  message: 'User with email test@test.com not found',
  stack: error.stack,  // Stack trace exposed!
}

// ✅ Safe: Minimal information only
{
  code: 'NOT_FOUND',
  message: 'User not found.',
}

// Detailed logs only on server
console.error(`User not found: ${email}`, error);
Rate Limiting
typescript
// middleware.ts
import { Ratelimit } from '@upstash/ratelimit';

const ratelimit = new Ratelimit({
  redis: Redis.fromEnv(),
  limiter: Ratelimit.slidingWindow(10, '10 s'),
});

export async function middleware(request: NextRequest) {
  const ip = request.ip ?? '127.0.0.1';
  const { success } = await ratelimit.limit(ip);

  if (!success) {
    return new Response('Too Many Requests', { status: 429 });
  }
}

Environment Variable Security (Phase 2/9 Connection)

Client Exposure Check
typescript
// lib/env.ts
const serverEnvSchema = z.object({
  DATABASE_URL: z.string(),      // Server only
  AUTH_SECRET: z.string(),       // Server only
});

const clientEnvSchema = z.object({
  NEXT_PUBLIC_APP_URL: z.string(),   // Can be exposed to client
});

export const serverEnv = serverEnvSchema.parse(process.env);
export const clientEnv = clientEnvSchema.parse({
  NEXT_PUBLIC_APP_URL: process.env.NEXT_PUBLIC_APP_URL,
});
Security Header Configuration
javascript
// next.config.js
const securityHeaders = [
  { key: 'Strict-Transport-Security', value: 'max-age=63072000' },
  { key: 'X-Frame-Options', value: 'SAMEORIGIN' },
  { key: 'X-Content-Type-Options', value: 'nosniff' },
  { key: 'Referrer-Policy', value: 'origin-when-cross-origin' },
];

module.exports = {
  async headers() {
    return [{ source: '/:path*', headers: securityHeaders }];
  },
};

Security Verification Checklist (Phase 8 Connection)

Required (All Levels)
  • HTTPS enforcement
  • No sensitive info exposed to client
  • Input validation (server-side)
  • XSS defense
  • No sensitive info in error messages
  • CSRF token applied
  • Rate Limiting applied
  • Security headers configured
  • httpOnly cookies (auth token)
Advanced (Enterprise)
  • Content Security Policy (CSP)
  • Security audit logs
  • Regular security scans

Next.js SEO Example

tsx
// app/layout.tsx
export const metadata: Metadata = {
  title: {
    default: 'Site Name',
    template: '%s | Site Name',
  },
  description: 'Site description',
  openGraph: {
    type: 'website',
    locale: 'en_US',
    url: 'https://example.com',
    siteName: 'Site Name',
  },
};

Template

See templates/pipeline/phase-7-seo-security.template.md

Next Phase

Phase 8: Review → After optimization, verify overall code quality

© ww-w-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/phase-7-seo-security of ww-w-ai/bkit-claude-code.

Open the folder on GitHubat commit 85b4913

Compare with similar skills

Phase 7 SEO Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Phase 7 SEO Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Phase 7 SEO Security this skillww-w-ai/bkit-claude-code601—~2.3kAutomated safety check: PassApache-2.0
Moai Ref SEOmodu-ai/moai-adk1.2k—~3.3kAutomated safety check: PassApache-2.0
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
SEO Keyword ClusteringAgriciDaniel/claude-seo19k2 repos~3.3kAutomated safety check: PassMIT
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
SEO Content Brief GeneratorAgriciDaniel/claude-seo19k2 repos~2.6kAutomated safety check: PassMIT

Similar skills

  • Moai Ref SEO

    modu-ai/moai-adk

    Search-visibility and crawlability reference for web output: canonical URL discipline, per-page title and meta description uniqueness, robots.txt and sitemap.xml as host-derived artifacts, JSON-LD…

    1.2k GitHub stars~3.3k tokensUpdated yesterday
    Marketing & SEOAuto-check passed
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • SEO Keyword Clustering

    AgriciDaniel/claude-seo

    Clusters keywords by how much their search results overlap and designs a hub-and-spoke content plan with an internal link matrix and an interactive cluster map.

    19k GitHub starsUsed in 2 repos~3.3k tokens
    Marketing & SEOAuto-check passed
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • SEO Content Brief Generator

    AgriciDaniel/claude-seo

    Builds research-backed SEO content briefs with competitor scoring, per-section word counts and page-type templates, for new pages or improving existing ones.

    19k GitHub starsUsed in 2 repos~2.6k tokens
    Marketing & SEOAuto-check passed
  • Remove bracketed NemoClaw tags from GitHub issue and PR titles.

    23k GitHub stars~693 tokensUpdated today
    Marketing & SEOAuto-check passed

More from ww-w-ai/bkit-claude-code

All 44 skills in this repo
  • Audit

    ww-w-ai/bkit-claude-code

    View audit logs, decision traces, and session history for AI transparency.

    601 GitHub stars~1.6k tokensUpdated 14 days ago
    Auto-check: notes
  • Bkend Auth

    ww-w-ai/bkit-claude-code

    bkend.ai authentication — email/social login, JWT tokens, RBAC, session management.

    601 GitHub stars~937 tokensUpdated 14 days ago
    Auto-check: notes
  • Bkend Cookbook

    ww-w-ai/bkit-claude-code

    bkend.ai project tutorials (todo to SaaS) and common error troubleshooting.

    601 GitHub stars~891 tokensUpdated 14 days ago
    Auto-check: notes
  • Bkend Quickstart

    ww-w-ai/bkit-claude-code

    bkend.ai onboarding — MCP setup, resource hierarchy, tenant/user model, first project.

    601 GitHub stars~1.2k tokensUpdated 14 days ago
    Auto-check passed
  • Bkend Storage

    ww-w-ai/bkit-claude-code

    bkend.ai file storage — upload (presigned URL), download (CDN), visibility levels, buckets.

    601 GitHub stars~901 tokensUpdated 14 days ago
    Auto-check: notes
  • Bkit

    ww-w-ai/bkit-claude-code

    bkit plugin help - list available functions including /pdca (9-phase feature cycle), /sprint (8-phase feature container, v2.1.13), /control (Trust L0-L4 + SPRINTAUTORUNSCOPE), /bkit-explore, and 40+…

    601 GitHub stars~1.4k tokensUpdated 14 days ago
    Auto-check passed

Questions about Phase 7 SEO Security

What does Phase 7 SEO Security do?

Enhance SEO (meta tags, semantic HTML) and security (vulnerability checks, hardening). Phase 7 SEO Security is an agent skill from ww-w-ai/bkit-claude-code. Enhance SEO (meta tags, semantic HTML) and security (vulnerability checks, hardening).

When should I use Phase 7 SEO Security?

Phase 7 SEO Security fits situations like: tasks that involve On-page SEO; tasks that involve Web application vulnerabilities.

How do I install Phase 7 SEO Security in Claude Code?

Run `npx skills add ww-w-ai/bkit-claude-code --skill phase-7-seo-security -a claude-code`. Or copy the skill folder (skills/phase-7-seo-security in ww-w-ai/bkit-claude-code) into .claude/skills/phase-7-seo-security in your project. Claude Code loads it when a task matches its description.

How do I install Phase 7 SEO Security in Codex?

Run `npx skills add ww-w-ai/bkit-claude-code --skill phase-7-seo-security -a codex`. Or copy the skill folder (skills/phase-7-seo-security in ww-w-ai/bkit-claude-code) into .agents/skills/phase-7-seo-security in your project. Codex loads it when a task matches its description.

Can I use Phase 7 SEO Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ww-w-ai/bkit-claude-code --skill phase-7-seo-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/phase-7-seo-security, .gemini/skills/phase-7-seo-security, .github/skills/phase-7-seo-security and .opencode/skills/phase-7-seo-security in your project.

What does Phase 7 SEO Security need to run?

Going by SKILL.md and its folder, Phase 7 SEO Security needs credentials named AUTH_SECRET. Our summary lists: A credential in AUTH_SECRET. Its frontmatter pre-approves these tools: Read, Edit, Glob, Grep, WebSearch.

Does Phase 7 SEO Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Phase 7 SEO Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Phase 7 SEO Security use?

Phase 7 SEO Security is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Phase 7 SEO Security use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Phase 7 SEO Security?

Skills that share tags, products or a category with Phase 7 SEO Security: Moai Ref SEO (modu-ai/moai-adk, 1.2k stars), Security And Hardening (penpot/penpot, 61k stars), SEO Keyword Clustering (AgriciDaniel/claude-seo, 19k stars) and Security Review (jewbetcha/opentrace, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Phase 7 SEO Security?

ww-w-ai (a GitHub organization) maintains it in ww-w-ai/bkit-claude-code, which has 601 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on September 27, 2026.

Source: ww-w-ai/bkit-claude-code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.