The Snitch skills family, now on khuur.dev
The Snitch family of Claude Code skills now installs directly from khuur.dev. Each skill is a single tarball your assistant unpacks into ~/.claude/skills/, and each one triggers from plain language — you describe what you want audited, and the right skill loads.
What's in the family
- snitch — security audit for AI-written code. OWASP and CWE findings with
file:lineevidence, data-flow tracing, SARIF output, and compliance packs. Evidence, not vibes. - snitch-marketing — SEO and marketing audit held to the same standard: every finding carries a
file:lineor URL-plus-selector proof. Technical SEO, schema, AI-search citation, Core Web Vitals contributors, conversion and CRO, site architecture, brand SERP. - snitch-cloudflare / -aws / -azure / -digitalocean / -flyio / -railway / -vercel — audit, harden, and plan migrations for each cloud, plan-aware.
- ads-ready — set up and verify ad-platform tracking: pixels, Consent Mode v2, CAPI, and ads.txt across the major networks.
- claude-ready — make any repo Claude-ready: a tight CLAUDE.md, slash commands, a screenshot-and-test feedback loop, and a permissions allowlist.
New in snitch-marketing v1.5.0
This release deepens how the skill audits a site's standing in AI answer engines — ChatGPT, Claude, Perplexity, Gemini, and Google's AI Overviews — the work people call GEO. What's new:
- Citability scoring — a reproducible, per-passage score built from observable text features (answer placement, definitions, self-containment, statistic density, structure), with the quoted passage as the evidence.
- Answer-fitness by surface — checks that answers match the length each surface rewards: roughly 134–167 words for a citation passage, 40–60 for a featured snippet, under about 29 for voice.
- AI-crawler registry — the current set of AI crawler user-agents, with the distinction between training bots and live-retrieval bots, so a robots.txt finding names the actual consequence.
- Off-site authority sweep — a presence-and-recency checklist across the platforms assistants weight (Wikipedia, Reddit, YouTube, G2, and more).
- E-E-A-T assessment — Experience, Expertise, Authoritativeness, and Trust, mapped to Google's quality guidance with Trust weighted heaviest.
- An honest llms.txt stance — the file is low-cost and worth publishing, but it is not a confirmed citation lever, and the skill now says so rather than overstating it.
- Schema-deprecation awareness — it stops recommending retired rich-result types as if they still render.
- Content-intelligence metrics — readability, cross-page near-duplicate detection, and keyword cannibalization, each producing a quotable figure.
- An optional GEO readiness score — a transparent rollup where every point is traceable to a finding, not a black-box number.
Install
One skill:
curl -fsSL khuur.dev/skills/snitch-marketing | bash
Everything:
curl -fsSL khuur.dev/skills/install.sh | bash -s all
The full catalog, with sha256 hashes, lives at /skills.json. Browse the family at /skills.