Install
$ agentstack add skill-nocodework-growth-os-connect β scanned Β· β verified, works with Claude Code, Cursor, and more.
Security review
β PassedNo issues found. Passed automated security review. Β· v0.1.0 How review works β
- β Prompt-injection patterns
- β Secret / credential exfiltration
- β Dangerous shell & filesystem operations
- β Untrusted network calls
- β Known-malicious package signatures
What it can access
- β Network access No
- β Filesystem access No
- β Shell / process execution No
- β Environment & secrets Used
- β Dynamic code execution No
From automated source analysis of v0.1.0. βUsedβ means the capability is present in the source β more access means more to trust, not that itβs unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work βAbout
connect
The integration wizard. Connecting analytics and ad accounts is where most tools lose people β the approval flows are confusing, some take weeks, and it's never clear what you can start right now. connect fixes that by telling you exactly what's fast, what's slow, and walking you through each one in the right order.
What it does
- Detects which credentials are already present in
.envand which sources are live. - Classifies every source as π’ (zero-approval, minutes) or π΄ (needs an owner-side approval with real lead time).
- Sequences the setup so the user gets value today: do all the π’ sources now, kick off the π΄ approvals in parallel so their clock starts.
- Guides each connection step by step, linking to the matching
docs/integrations/*page. - Separates the two very different kinds of approval so nobody waits on the wrong thing.
The two kinds of approval β this is the key distinction
- Developer approval (once, ever). A one-time setup the account owner does at the platform level β a developer token, a verified business, an app that passes review. Slow, but you do it once and it's done for the whole org. These are the π΄ sources.
- User OAuth (per person, fast). An individual granting read access to their own data via a consent screen. Seconds to minutes. These are the π’ sources (plus, later, the read grant on the π΄ platforms once the developer approval exists).
Conflating these is why integrations feel painful. connect keeps them apart and tells the user which clock they're on.
The sources
π’ Zero-approval β start now, minutes each
- GA4 (Data API) β service-account JSON added to the property, or OAuth with
analytics.readonly. βdocs/integrations/ga4.md - Google Search Console β
webmasters.readonly, the same service account added as a user on the property. βdocs/integrations/gsc.md - MailerLite β Bearer API key generated in the MailerLite UI. β
docs/integrations/mailerlite.md - PageSpeed Insights β an API key from a Google Cloud project. β
docs/integrations/pagespeed.md
π΄ Needs approval β owner-side, real lead time, start in parallel
- Google Ads β a developer token on a Manager (MCC) account. Test/Explorer access works to start; Basic access needs Google's sign-off. β
docs/integrations/google-ads.md - Meta Marketing / Graph (+ Instagram) β Business Verification first (~14+ days), then App Review for
ads_read/instagram_*scopes. βdocs/integrations/meta.md
Steps
- Scan
.env. Report what's already wired: "GA4 β , PageSpeed β , MailerLite β, Search Console ββ¦" so the user sees the current state at a glance.
- Explain the two clocks. Briefly: the π’ sources take minutes and unlock most of the audit; the π΄ sources need owner-side approvals that take days-to-weeks, so we start those in the background and don't wait on them.
- Do the π’ sources first, one at a time. For each missing π’ source: open its
docs/integrations/*page, walk the exact steps (create key / add service account / paste into.env), then verify the connection with a smoke call (growth-os ga4 visitors 7,growth-os psi, etc.). Confirm it works before moving to the next. Don't dump all four at once β one clean win at a time.
- Kick off the π΄ approvals. For Google Ads and Meta, explain what the owner needs to start today so the lead-time clock begins β especially Meta Business Verification, which gates everything else and is the long pole. Point them at the docs, note it's a one-time developer approval, and mark the source "pending" in the current state. Make clear they don't need to finish this to keep going.
- Summarize the new state. What's live, what's pending, and what that unlocks: "GA4 + GSC live β the audit now has a real baseline. Meta pending verification β ads reach data lands in ~2 weeks." Route back to
/growth-os:audit(re-run with the new data) or/growth-os:dashboard(see integration status).
Which adapters / CLI it calls
- Verifies each connection with the matching read-side smoke command:
growth-os ga4 β¦,growth-os gsc β¦,growth-os mailerlite β¦,growth-os psi β¦, and (once approved)growth-os google-ads β¦,growth-os meta β¦. - Reads and writes
.envonly for credentials β never the hub, never anywhere remote. - References
docs/integrations/*for the human steps.
How it delegates
- In: called by
onboardduring first-run, and byaudit/dashboardwhen a needed source is missing. - Out: once a source connects, hands control back to whatever needed it (usually
audit). Doesn't do analysis itself β it's plumbing.
Guardrails
- Keys stay local. Everything goes in the user's
.env. Growth OS stores no credentials and phones nothing home. - Never block on π΄. The fast sources always run first and independently; slow approvals proceed in parallel.
- Verify, don't assume. A source is only "connected" after a live smoke call succeeds.
- Read scopes only. Every scope Growth OS requests is read-only (
analytics.readonly,webmasters.readonly,ads_read, etc.). It never asks for write access to a user's accounts.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source β we do not rehost the code.
- Author: nocodework
- Source: nocodework/growth-os
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.