Local business site builder (Greece)
Distilled from a real site (Αποφράξεις Τσαβάρης) that took dozens of prompts because the invisible plumbing went wrong again and again: server config, consent, SEO files, inconsistent facts. Goal: get it right the first time. Talk to the user in Greek.
Paths below are relative to this skill's folder. Resolve them to absolute paths before running scripts; run scripts with deno run -A scripts/<name>.mjs (or node). If neither exists, tell the user (install: winget install DenoLand.Deno, ask first) and use the manual checklists.
Portable execution
Check the host capabilities before running helpers: terminal and file access, Node 18+ or Deno, browser tooling, optional FFmpeg and network permissions. Never assume installation supplies these tools. Use available equivalent image/browser tools or manual reference checklists; report any automated checks you could not execute. Resolve every supporting path against this installed skill directory. Never assume a Windows user path or install software without authorization.
Rules that never bend (each cost real time or money)
- Never invent facts. Phone, email, address, ΑΦΜ, ΓΕΜΗ, hours, prices, reviews, ratings, years in business, licences, guarantees, arrival times come from the owner. Missing → ask, or leave out;
[ΧΡΕΙΑΖΕΤΑΙ: …]markers block go-live. Regulated professions (doctor, dentist, lawyer, pharmacist): no reviews, no success claims (references/01 §4). - One source of truth:
site-facts.json(outside the deploy folder). Derived files (JSON-LD, sitemap, llms.txt, robots, manifest, vCard) are regenerated withscaffold.mjs derive, never hand-edited. - Design is decided per client, never copied from a previous site: write
docs/DESIGN.md, get the user's pick of ONE direction, then code (references/02). - CSP-clean from line one: no inline script/style/handlers; every third party added to the CSP in the same change; one enforced CSP.
- No third-party request before consent or a click. GA4 loads only after "Αποδοχή"; Accept/Reject equal; map on click; fonts self-hosted with verified Greek glyphs (many popular fonts, e.g. Poppins/Montserrat, have none).
- Fix root causes, not per-width patches. Mobile-first; test the width matrix with
scripts/overflow_probe.js. - Never trust a server directive. Hostinger/LiteSpeed ignores
<IfModule>, silently ignores unsupported directives and forces HTTPS at the edge: verify live withverify_live.mjs. - SEO files are deliverables: canonical, robots (
Allow: /+ Sitemap), sitemap, JSON-LD (LocalBusiness subtype), OG 1200×630, icons incl. maskable. - Bump
?v=on every page after any CSS/JS change (bump_version.mjs) and purge Hostinger caches. - Verify, don't assume. Say "done" only after the audit shows 0 errors on the final files, browser QA is done, and you report honestly what is unverified.
Gotchas (obsolete or false beliefs that look right)
- FAQPage/HowTo markup brings nothing: FAQ rich results were retired on 7 May 2026.
llms.txthas no proven effect (Google says it does not use it): optional. - Never add
aggregateRating/reviewJSON-LD for the business itself;sameAsonly for real, populated profiles (never an empty second domain). - A staging
Disallow: /ornoindexleft in production deindexes the site (audit SEO-001/023). - Hostinger preview domain
*.hostingersite.comduplicates the site: 301 it and remove it. htaccesswithout the dot is ignored; with a dot it must be uploaded explicitly (hidden file). Docs/facts/.mdmust not sit inpublic_html.- Google Fonts CDN links break privacy and CSP; frontend design advice that names Poppins/DM Sans/Playfair etc. fails on Greek.
- A link that differs from a file only by letter case works on Windows and 404s on the server.
- Anchors built inside JS (cookie banner →
/privacy.html#cookies) must exist too. - The edge bot challenge after ~60 quick requests is not a site failure: wait, don't bypass.
Workflow (load the reference named in each step before doing it)
- Triage: new site · rework · audit-only (jump to 6) · small change (jump to 5). Check which tools exist (deno/node, browser tool, ffmpeg, Edge/Chrome for
render_png). - Intake → read
references/01-intake-and-facts.md. Ask everything in one Greek message (if nobody can answer, use only the facts given, never invent, writeQUESTIONS.md); writesite-facts.jsonfromassets/site-facts.example.json;scaffold.mjs check --facts site-facts.json. - Design brief →
references/02-design-direction.md; filldocs/DESIGN.md, propose 2-3 directions, get a choice. - Scaffold:
scaffold.mjs init --facts site-facts.json --out public --docs docs [--logo logo.svg](creates pages, base CSS, JS,.htaccesswith CSP from the features, robots, sitemap, llms.txt, manifest, vCard, Greek handoff docs, AGENTS.md/CLAUDE.md for the project). - Build →
references/03-build-and-code.md,04-conversion-and-content.md,05-seo-schema-geo.md: tokens + THEME instyle.css, sections inindex.html(replace the[ΧΡΕΙΑΖΕΤΑΙ…]marker), assets viamake_icons.mjs,render_png.mjs(OG image from an HTML page),images.mjs,font_greek_check.mjs --download. For consent, privacy text, footer identity, prices or reviews also read06-privacy-consent-legal.md. A finished fictional example of the quality bar is inassets/example-site/(study structure and copy tone, never its look). - After any fact change: facts →
scaffold.mjs derive→ visible text →bump_version.mjs. - Audit:
audit_site.mjs public --facts site-facts.json→ fix every ERROR, read WARN, give the owner the VERIFY list. Unclear finding →references/mistake-registry.md. - QA and launch →
references/08-qa-and-launch.md(width matrix, consent test, content QA); deploy and server details inreferences/07-server-htaccess-deploy.md. - Post-deploy:
verify_live.mjs https://DOMAIN --local public --preview-domain X.hostingersite.com; hand the ownerdocs/. Forms, booking, more pages, CMS, e-shop, other languages, ads pixels →references/09-beyond-the-basics.mdand agree scope first.
Scripts (scripts/)
audit_site.mjs pre-launch audit (ERROR/WARN/VERIFY/INFO; --json, --strict; exit 1 on errors) · verify_live.mjs live check (redirects, headers, 404, exposed files, byte-identity; throttled) · scaffold.mjs init/derive/check · bump_version.mjs · render_png.mjs · make_icons.mjs · images.mjs (ffmpeg) · contrast.mjs · font_greek_check.mjs · overflow_probe.js (run inside the page). All print --help-style usage when called without arguments. They write only inside the folders you pass.
Reference index
01 intake/facts/regulated professions · 02 design directions, Greek fonts · 03 build, performance, accessibility, widths · 04 conversion and copy · 05 SEO/schema/GBP/AI search · 06 privacy and Greek law pointers · 07 Hostinger server and deploy · 08 QA/launch · 09 beyond the basics · mistake-registry. Research date: 2026-10-05; laws and Google policies change: re-verify before relying on them, and say when something is unverified.