Install
$ agentstack add skill-sergekostenchuk-ui-ux-agent-skill-system-serp-source-configurator ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
SERP Source Configurator
This skill owns the setup gate before search-demand collection. It does not harvest keywords itself; it creates a redacted, approval-aware source configuration and hands it to serp-keyword-harvester.
Operating Modes
design-ui: define user-facing fields, checkboxes, statuses, and safe defaults for a source settings panel.configure: create or update a redactedreports/serp-source-config.json.preflight: check OpenSERP/base URL/proxy readiness and recordRan,Skipped, orPlanned.budget-gate: set query limits, engine limits, cache TTL, timeout, and paid-proxy rules.audit: review an existing source config for secrets, missing approvals, unsafe paid settings, or unclear handoff.
Required Workflow
- Read [references/decision-framework.md](references/decision-framework.md).
- If proxy providers, API keys, OpenSERP, AKE, paid traffic, or external network calls are involved, read [references/safety-boundaries.md](references/safety-boundaries.md).
- For UI/dashboard requests, use [references/ui-controls.md](references/ui-controls.md) and [assets/source-config.template.json](assets/source-config.template.json).
- Classify sources:
- local/manual inputs: allowed by default;
- direct OpenSERP engines: approval required before external queries;
- proxy-backed engines: approval plus budget and proxy precheck required;
- paid or account-mutating provider actions: explicit confirmation immediately before action.
- Never store API keys, proxy credentials, cookies, recovery codes, or
.envvalues in Markdown, HTML, task plans, wiki notes, reports, screenshots, or exported JSON. - Write only redacted configuration and runtime references such as
env:AKE_API_KEY. - Validate the source config with [scripts/validateserpsourceconfig.py](scripts/validateserpsourceconfig.py).
- Hand off to
serp-keyword-harvesteronly after approval, selected engines, limits, and failure behavior are explicit.
System Role
Use this skill between the SEO/site architecture layer and the keyword harvester:
seo-llm-site-architect
-> serp-source-configurator
-> serp-keyword-harvester
-> semantic-core-builder
serp-source-configurator owns source settings, proxy gates, credential handling, budget limits, and preflight status. serp-keyword-harvester owns actual keyword/SERP evidence collection.
Output Standard
Mode:
Selected sources:
Disabled sources:
Proxy mode:
Credential handling:
Approval status:
Budget limits:
Preflight:
Output config:
Skipped/planned checks:
Next skill: serp-keyword-harvester
Safety Rules
- Treat OpenSERP and provider APIs as
external-network. - User-entered API keys are runtime inputs only; redact them before any artifact is written.
- Do not create, refresh, rotate, buy, or mutate provider proxy ports unless the user explicitly asks for that specific action.
- Prefer direct/free engines first. Use paid proxy only for engines that need it, usually Google/Yandex.
- If proxy precheck fails, keep proxy sources
Skippedand continue with direct/manual sources. - Do not retry paid proxy failures aggressively.
Validation
When editing this skill, run:
python3 $CODEX_HOME/skills/.system/skill-creator/scripts/quick_validate.py $CODEX_HOME/skills/serp-source-configurator
python3 $CODEX_HOME/skills/senior-skill-architect/scripts/lint_production_skill.py $CODEX_HOME/skills/serp-source-configurator
python3 $CODEX_HOME/skills/serp-source-configurator/scripts/validate_serp_source_config.py $CODEX_HOME/skills/serp-source-configurator/assets/source-config.template.json
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: sergekostenchuk
- Source: sergekostenchuk/ui-ux-agent-skill-system
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.