fix(seo): I4 — stop double-counting security headers; /harden owns them
Headers were scored three ways: seo-analyzer priced them into the Technical axis at both depths (:619 FULL, :635 LOCAL), depth-matrix.md:29 said drop them, and /harden re-audits them 0-100 against three external validators. The dedup rule and the agent spec contradicted each other; the agent won by default, so the same finding moved two scores in two reports. Arbitrated (user): /harden keeps them, /seo drops them. That confirms the rule that already existed — seo-analyzer was the violator. Constraint: /harden REUSES seo-analyzer, so the capability cannot be deleted, only scoped. Reading is not scoring: - Technical axis definitions no longer name security headers. - STEP 4 still curls them — needed for X-Robots-Tag, canonical/redirect coherence, and the §14 observed-list — but they earn no points under /seo. - Dispatched from /harden: unchanged, headers ARE the job (verified: its scope spec untouched, 16 header references intact). Carve-out: X-Robots-Tag stays in /seo under indexability. It is an indexing directive wearing a header's clothes — `noindex` there deindexes as surely as a meta robots tag. That is what depth-matrix.md:29 means by "unless it directly affects indexability"; the security headers do not. Drop is not silence: mandatory §14 line on FULL naming what was observed live plus a "run /harden <url>" pointer. A user who never runs /harden must not read a clean Technical score as clean headers — same principle as the mandatory COVERAGE line (I5). Verified: make test 35 GREEN / 0 RED.
This commit is contained in:
@@ -348,6 +348,15 @@ audit GEO/AI signals (llms.txt, AI crawlers, QAPage/Speakable schemas,
|
||||
entity SEO, content shape for AI, AI visibility) — the geo-analyzer
|
||||
agent runs in parallel and owns those.
|
||||
|
||||
Do NOT score security headers either (CSP, HSTS, X-Frame-Options,
|
||||
X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP/CORP,
|
||||
cookie flags) — `/harden` owns them and grades them 0-100 against three
|
||||
external validators (`depth-matrix.md:29`). Read them, keep
|
||||
`X-Robots-Tag` under indexability (it is an indexing directive, not a
|
||||
security header), and declare the rest in §14 with a "run /harden" pointer
|
||||
plus what you observed live. Dropping them from the score must not make
|
||||
them silent.
|
||||
|
||||
FILE OWNERSHIP (authoritative, prevents parallel-edit conflicts):
|
||||
- YOU OWN (read+write): sitemap.xml, image/video sitemaps, .htaccess,
|
||||
meta tags (title, description, OG, Twitter, canonical, robots meta),
|
||||
|
||||
Reference in New Issue
Block a user