Skip to content

Two words of coincidence is not evidence, and a construction is not an article - #213

Merged
ralyodio merged 1 commit into
masterfrom
autoblog-keyword-quality
Aug 28, 2026
Merged

ralyodio merged 1 commit into
masterfrom
autoblog-keyword-quality

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Follow-up to #212, from reading its first production output.

The hourly cron wrote 162 keywords across 11 sites and 41 subjects. The vendor
and junk classes are gone — no home-alarm companies on vu1nz, no lawn mowers on
pairux, no stock tickers on bittorrented. Two problems remained that fixtures
could not have surfaced.

Partial matches leaked (8 of 162)

One generic word of a multi-word subject matched, and a generic tail word
rescued it:

site leaked matched only
logicsrc open broadcaster software, open source software "open" of "open standards"
vu1nz industrial automation supply "supply" of "supply chain security"
c0upons quickbooks online pricing "online" of "online shopping"
ugig software engineer remote "remote" of "remote work"

A partial match on a multi-word subject may now only be rescued by an anchor
the site itself supplied, never by DEFAULT_MODIFIERS. Complete matches are
unaffected — including single-word subjects, where iptv alternatives is a
real query.

The cross-product floor was publishing constructions

Used as per-subject filler it produced saving money pricing, deals platform, coordination d0rz, ai content loop. On-niche, gate-passing, and
not topics anybody searches. bl0ggers' niche is "human-in-the-loop AI
publishing", so its derived modifiers are literally human and loop.

Crosses still seed every DataForSEO expansion — that was always their real
value, and it is what turns "peptide" into "peptide merchant account". They are
now a site-level last resort rather than per-subject filler: only a run that
would otherwise insert nothing falls back to them. usedCrossFloor is reported
so a site stuck there is visible.

Verification

1931 tests pass, tsc --noEmit clean, next build compiles. All 8 leaked
keywords are pinned as regressions alongside the on-niche keywords from the
same run that must still pass.

🤖 Generated with Claude Code

https://claude.ai/code/session_013cbcXdpLFUgJZuVfCB4Gzv

…n article

The anchored gate shipped and the hourly cron wrote its first 162 keywords
across 11 sites. The vendor and junk classes are gone. Reading the actual
output found two things the fixtures could not have.

**Partial matches leaked.** Eight keywords, all one shape: one generic word of
a multi-word subject matched, and a word from the generic commercial
vocabulary rescued it. "open standards" matched on "open", "software" did the
rest, and logicsrc was queued to write about OBS Studio. "supply chain
security" matched on "supply" and admitted "industrial automation supply".
"online shopping" matched on "online" and admitted "quickbooks online
pricing". So a partial match on a multi-word subject may now only be rescued
by an anchor the site itself supplied — never by the defaults, which are
generic by construction. A complete match is unaffected, including a
single-word subject, where "iptv alternatives" is a real query.

**And the cross-product floor was publishing constructions.** That one is mine
and it was new. Used as per-subject filler it produced "saving money pricing",
"deals platform", "coordination d0rz" and "ai content loop" — on-niche,
gate-passing, and not topics anybody searches. bl0ggers' niche is
"human-in-the-loop AI publishing", so its derived modifiers are literally
"human" and "loop", and crossing a subject with those yields nonsense.

The crosses' real value was always upstream: as DataForSEO seeds they are what
turns "peptide" into "peptide merchant account", and they still seed every
expansion. They are simply no longer published on the strength of being
grammatically adjacent to the niche. They remain the floor, but site-level
rather than per-subject — only a run that would otherwise insert nothing falls
back to them, which keeps "a blog with every upstream down still publishes"
without letting constructions pad a healthy run. The result reports
usedCrossFloor so a site sitting on that for weeks is visible.

All eight leaked keywords are now regression cases, with the on-niche
keywords from the same run that must still pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013cbcXdpLFUgJZuVfCB4Gzv
@ralyodio
ralyodio merged commit f1c7e91 into master Aug 28, 2026
7 checks passed
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

39 finding(s)

HIGH/CRITICAL: 3 | MEDIUM: 27 | LOW: 9

Severity Rule Location
HIGH tls-verification-disabled lib/onion.ts:47
HIGH secret-generic-credential lib/sp/platforms/facebook.ts:32
HIGH sh-remote-script-execution prober/deploy/provision.sh:30
MEDIUM js-unescaped-html-sink app/(app)/dashboard/admin/email-broadcast/EmailBroadcastForm.tsx:125
MEDIUM js-unescaped-html-sink app/(app)/dashboard/projects/[id]/autoblog/articles/[articleId]/page.tsx:214
MEDIUM js-unescaped-html-sink app/(marketing)/blog/[slug]/page.tsx:67
MEDIUM js-unescaped-html-sink app/(marketing)/blog/[slug]/page.tsx:97
MEDIUM js-unescaped-html-sink app/(marketing)/blog/[slug]/page.tsx:104
MEDIUM js-unescaped-html-sink app/(marketing)/blog/[slug]/page.tsx:110
MEDIUM js-unescaped-html-sink app/(marketing)/recent/page.tsx:186
MEDIUM js-unescaped-html-sink app/(marketing)/recent/page.tsx:190
MEDIUM js-unescaped-html-sink app/c/[project]/[slug]/page.tsx:77
MEDIUM js-unescaped-html-sink app/c/[project]/page.tsx:57
MEDIUM js-unescaped-html-sink app/careers.js/route.ts:228
MEDIUM js-unescaped-html-sink app/careers.js/route.ts:285
MEDIUM js-unescaped-html-sink app/layout.tsx:129
MEDIUM js-open-redirect app/login/form.tsx:39
MEDIUM js-unescaped-html-sink app/r/[token]/page.tsx:176
MEDIUM js-open-redirect app/signup/form.tsx:43
MEDIUM js-open-redirect components/billing/buy-credits-modal.tsx:98
MEDIUM js-unescaped-html-sink components/json-ld.tsx:8
MEDIUM js-unescaped-html-sink components/report/markdown-view.tsx:15
MEDIUM redos-nested-quantifier lib/careers/jobs.ts:139
MEDIUM js-unescaped-html-sink lib/careers/page-templates.ts:198
MEDIUM redos-nested-quantifier lib/emailMarkdown.ts:130
MEDIUM redos-nested-quantifier lib/lx/articleGen.ts:98
MEDIUM redos-nested-quantifier lib/sp/parseHandle.ts:92
MEDIUM redos-nested-quantifier lib/tracker/agent-gate.ts:61
MEDIUM sql-template-interpolation scripts/detect-slot-themes.ts:31
MEDIUM sql-template-interpolation scripts/purge-offniche-keywords.ts:124
LOW secret-generic-credential app/(marketing)/docs/autoblog-webhook/page.tsx:145
LOW secret-generic-credential lib/sp/platforms/linkedin.ts:25
LOW js-dynamic-code-execution tests/careers-page-templates.test.ts:21
LOW js-dynamic-code-execution tests/careers-widget-script.test.ts:19
LOW js-dynamic-code-execution tests/careers-widget-script.test.ts:69
LOW js-dynamic-code-execution tests/contract/ad-visitor-id.test.ts:51
LOW js-dynamic-code-execution tests/contract/ad-visitor-id.test.ts:52
LOW secret-generic-credential tests/contract/posthog-integration.test.ts:13
LOW secret-generic-credential tests/lead-campaign.test.ts:16

Snippets are redacted; ThreatCrush never prints matched credential material.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants