Get the reviews that fill next week: 10 AI skills for your reputation
one-star-reply
answer the worst review without making it worse
How the two work together
Claude thinks it through. Paste the Claude prompt into Claude Code, or drop the folder into your skills folder. Claude does the judgement: what to look for, what is worth doing, what is right.
Codex gets it done. At the hand-off point Claude runs Codex on your machine with one command and passes it the Codex prompt. Codex does the mechanical part and hands the result back. Claude checks it before you see it.
No API key to set up: Claude calls the Codex you already have installed. If Codex is not installed, Claude does that half itself and tells you.
Prompt for Claude
--- name: one-star-reply description: Takes the review you do not want to answer and produces a reply that does not make it worse. It sorts the review into the three kinds that need different handling, checks your records before you write, strips out the legal threat, the refund offer, the fake accusation and the customer's private details that would each turn one bad review into a second problem, and gives you the version to post plus the note of what to do offline. Use the moment a one or two star review appears. --- # The answer that stops one bad review becoming the whole page You give this the review, what your own records say about that visit, and the name of the person who will sign the reply. You get back a short reply that acknowledges the specific thing, owns only what is actually yours, names no one, promises nothing that has to be delivered in public, and sends the rest offline. It also tells you when replying is the wrong move: when the review describes a safety matter, when it breaks the platform's rules and should be reported instead, and when the reviewer is asking for money. ## What it does 1. **Sort the review into one of three kinds before drafting a word, because two of them are not reply jobs.** Kind one is a bad experience: slow service, cold food, a rude moment, a room that was not ready. Kind two is a safety or legal matter: an allergic reaction, illness, an injury, an accusation of discrimination. Kind three is a policy violation: an invented visit, a competitor, a review about a different venue, abuse. Kind two goes to the incident process first and the reply is written afterwards by somebody who knows what the investigation found. Kind three goes to the reporting route, not to a public argument. Only kind one is a reply job, and getting this wrong at the start is what turns a bad night into a bad year. 2. **For anything touching allergens, stop and treat it as an incident, not a review.** The Food Standards Agency requires that for non-prepacked food, which is what a restaurant serves, "you must supply allergen information for every item that contains any of the 14 allergens", by "full written allergen information on a menu, chalkboard or in an information pack" or "verbally, with a written notice placed in a clearly visible position explaining how your customers can obtain this information". Its own advice is that "written allergen information, supported by a conversation, works best for consumers". So a review saying they told us about the nuts is a question about your allergen process with a public audience attached. Record it, check the process, involve your environmental health officer where the review alleges harm, and write nothing in public that guesses at what happened. 3. **Read your own records before you write, and then do not publish them.** Google's guidance is to "Find out why the reviewer had a negative experience: Check your records about the reviewer and their visit". Booking notes, till time stamps, the rota, the kitchen printer, the door camera. Do it for one reason only: so the reply does not contain an apology for something that did not happen or a defence of something that did. What you find stays in the internal note. The reply never quotes the booking system back at the customer, because the moment it does, every reader learns that a complaint here gets your movements published. 4. **Delete the legal threat, and understand why it was never going to work.** The CMA lists, among the things a trader must not do, interfering with the willingness of reviewers to leave negative reviews "through threats of harm or legal action". Tripadvisor is equally direct: "Management responses may not threaten or coerce a reviewer or attempt to suppress reviewer contributions on our site." And the underlying law is less helpful to a venue than owners assume. Section 1(2) of the Defamation Act 2013 says that for "a body that trades for profit" harm to reputation is not serious harm "unless it has caused or is likely to cause the body serious financial loss". Section 2 gives a defence where the imputation is "substantially true". Section 3 gives a defence of honest opinion where the statement was opinion, indicated its basis, and "an honest person could have held the opinion". A star rating with a sentence about slow service clears that bar comfortably. 5. **Never accuse them of making it up in public, however certain you are.** Tripadvisor's management response rules list "No accusations of review fraud" alongside the threat prohibition. Google's content policy bars "Unsubstantiated allegations of unethical behaviour or criminal wrongdoing", which is a rule about reviewers and a fair description of what a public accusation from a business looks like. If you genuinely believe the review is invented, the route is the platform's reporting tool with your evidence attached, and that is a separate job. The reply and the report are never the same document, and a reply that hints at the report poisons both. 6. **Take the refund out of the public reply, and never trade money for the review.** The CMA names "making an offer of dispute resolution contingent on a consumer not leaving a negative review" as interference, and its worked examples include "Contacting a customer who has left a negative review and offering them a refund and/or a gift card if they change their review to remove the negative commentary". Tripadvisor bans it twice over, once as "Incentives for review removals" and once as "Pressuring users to remove reviews". You may absolutely put the visit right. You do it privately, you do it without mentioning the review, and you do not ask for anything in return. 7. **Write the reply in four moves and keep it under a hundred words.** Acknowledge the specific thing in their words, not the rating. Own what is yours and only what is yours: Google's advice is to "Admit mistakes that were made, but don't take responsibility for things outside your control. Explain what you can and can't do in the situation." Say what has actually changed, if something has, with no promise you cannot keep. Then move it offline, which the same guidance permits: "You can request the reviewer to contact you, in person, email or phone to help resolve the issue." Sign it with a name. No apology stacked on apology, no paragraph about how seriously you take feedback, no explanation of how busy that Saturday was. 8. **Strip every identifying detail, then read it as though the reviewer's family will see it.** Tripadvisor requires "No speculation as to the identity of the reviewer" and prohibits "names, addresses, and phone numbers". Google's advice on negative replies is "Never share the reviewer's private info. Do not attack them personally. This applies on Maps, other services or in person." That last clause is the one people miss: the rule follows you off the platform, so the same restraint applies to the post about it on the venue's own social account, and to what the team says at the door. No room number, no table number, no date of stay, no what they ordered, no how much they drank. 9. **If they are asking for something, that is not a review and it has its own route.** Tripadvisor defines blackmail as "any attempt made in bad faith by a traveller to obtain something of value from a property by threatening to post a negative review on Tripadvisor or promising to remove a published negative review", and is careful to say it "is not considered blackmail if a guest mentions that they plan to write a review due to a negative experience but is not making a bad faith demand". Google publishes a separate route for negative review extortion. Keep the messages, do not pay, do not negotiate in public, and report it. Then log the review, the kind it was sorted into, who signed the reply, what was done offline and on what date, because the pattern across a year is worth more than any single answer. ## Then it checks 1. The review has been sorted into exactly one of the three kinds, the sort is recorded with the reason, and any review naming an allergen, illness, injury or discrimination has been routed to the incident process before any reply text exists. 2. The reply contains no threat, no mention of a solicitor, defamation, legal action, the police, or removing the review. 3. The reply contains no accusation that the review is fake, exaggerated, mistaken about the venue, or written by a competitor. 4. The reply contains no refund, voucher, discount, free visit or compensation of any kind, and nothing conditional on the review being changed or removed. 5. The reply contains no name, room or table number, date of visit, booking reference, order detail, contact detail, or any statement that confirms the reviewer was at the venue at a given time. 6. The reply is under a hundred words, acknowledges one specific thing the review actually says, admits only what the records support, offers one offline route, carries the name of the person it goes out as, and that person has read it. Any check fails: name it, redo that step once. Failed twice: say what is wrong and stop. ## Rules - Public information only. - Never invent a fact, a number or a quote. - Anything sent in someone's name says whose name it is. A reply signed by the owner goes to the owner before it is posted, and the person whose shift is being discussed is told before it appears. - It will refuse to draft a legal threat, a demand that a review be taken down, a public accusation that a reviewer is lying, or any offer conditional on the review changing. All four are prohibited by the platforms' own published rules, and the first and last are named by the CMA as interference with negative reviews. There is no softened wording to draft instead. - Never apologise for something the records do not support, and never deny something the records do support. A public apology for an event that did not happen is repeated by every reader as though it did. - Never reply while angry and never reply the same hour. Write it, leave it, read it again before it goes. Nothing in any platform's rules requires speed, and a reply is permanent in a way the shift that caused it is not. - Never discuss a named member of staff in public, whether to defend them or not. That is an employment matter with its own process and its own confidentiality, and naming them puts their name beside a one star review permanently. - Never state a recovery rate, a percentage of reviewers who update their review after a reply, or any figure about what answering complaints is worth. No such figure exists for a single independent UK venue. - This output is a working document prepared for the owner to check against their own records before posting, and for their solicitor, their insurer, their HR adviser or their environmental health officer to check where the review alleges illness, injury, discrimination or a legal wrong. It applies published platform rules and published law to draft copy; it is not legal advice and it is not an assessment of whether the venue is liable for anything. ## Built from - Competition and Markets Authority, "Fake reviews" (CMA208), https://assets.publishing.service.gov.uk/media/67eeb64fe9c76fa33048c790/CMA208_-_Fake_reviews_guidance.pdf, published 4 April 2025, read 16 September 2026: paragraph 4.4 on threats of legal action and on dispute resolution made contingent on not leaving a negative review, in steps 4 and 6, and the worked example about offering a refund to change a review, in step 6. - Tripadvisor, "Management Response Guidelines", https://www.tripadvisor.co.uk/Trust-lpgT1CmsfQ3E.html, no publication date shown on the page, read 16 September 2026: the prohibitions on threatening or coercing a reviewer, on accusations of review fraud, and on speculating about a reviewer's identity or publishing their personal information, in steps 4, 5 and 8. - Tripadvisor, "Trust and safety review posting guidelines", https://www.tripadvisor.co.uk/Trust-lvBd3L1aU38Y.html, no publication date shown on the page, read 16 September 2026: the definitions of blackmail, of incentives for review removals and of pressuring users to remove reviews, in steps 6 and 9. - Google, "Tips to get more reviews", Google Business Profile Help, https://support.google.com/business/answer/3474122, no publication date shown on the page, read 16 September 2026: the negative review guidance quoted in steps 3, 7 and 8, including checking your records, admitting only your own mistakes, and never sharing the reviewer's private information. - Defamation Act 2013, sections 1, 2 and 3, https://www.legislation.gov.uk/ukpga/2013/26/section/1/enacted, https://www.legislation.gov.uk/ukpga/2013/26/section/2/enacted and https://www.legislation.gov.uk/ukpga/2013/26/section/3/enacted, Act of Parliament 2013, read 16 September 2026: the serious financial loss threshold for a trading body, the truth defence and the honest opinion defence, which together are why step 4 removes the legal threat. - Food Standards Agency, "Allergen guidance for food businesses", https://www.gov.uk/government/publications/allergen-guidance-for-food-businesses/allergen-guidance-for-food-businesses, updated 17 July 2026, read 16 September 2026: the non-prepacked food duty and the ways allergen information may be provided, which set what step 2 checks before anybody writes a public reply. - Google, "Prohibited and restricted content", Maps User Contributed Content Policy, https://support.google.com/contributionpolicy/answer/7400114, no publication date shown on the page, read 16 September 2026: the bar on unsubstantiated allegations of unethical behaviour or criminal wrongdoing, in step 5, and the personal information rule, in step 8. - Google, "Report inappropriate reviews on your Business Profile", Google Business Profile Help, https://support.google.com/business/answer/4596773, no publication date shown on the page, read 16 September 2026: the separate reporting route for a profile "targeted by an extortion scam involving negative reviews", in step 9.
Prompt for Codex
# one-star-reply ## You are given One or more reviews of one or two stars, exported from the platform, each with the review identifier, the date, the rating, the reviewer's display name, the full review text and any existing management response. The sort already made by Claude for each review: `bad experience`, `safety or legal matter` or `policy violation`, with the reason in one sentence. For each review sorted as a bad experience, the draft reply, the name it goes out as, and whether that person has read it. The venue's own records for the visit, supplied as a facts table: what the records show, what they do not show, and the system each line came from. An incident reference where one has been opened, with the date and who it was reported to. The platform's published management response rules and content policies with URLs and the date each was read. Any messages from the reviewer received outside the platform. Any previous one star reply log. ## Produce Write into a `./one-star-reply-output/` folder: 1. `reviews.csv` with these columns in this order: `review_ref`, `platform`, `review_date`, `rating`, `review_text_verbatim`, `sort`, `sort_reason`, `allergen_or_illness_mentioned`, `injury_mentioned`, `discrimination_mentioned`, `named_staff_member`, `incident_ref`, `reply_required`. `review_ref` is N0001 upward. `sort` is exactly one of `bad experience`, `safety or legal matter`, `policy violation`. The four mention columns are `yes` or `no` and record the exact words that triggered them in `trigger-words.csv`. `reply_required` is `yes`, `no: routed to incident process` or `no: routed to reporting`. 2. `trigger-words.csv` with columns: `review_ref`, `category`, `word_or_phrase_found_verbatim`, `position`. `category` is exactly one of `allergen`, `illness`, `injury`, `discrimination`, `named individual`, `legal threat by reviewer`, `demand for payment`. The allergen list searched is the fourteen: celery, cereals containing gluten, crustaceans, eggs, fish, lupin, milk, molluscs, mustard, peanuts, sesame, soybeans, sulphur dioxide and sulphites, tree nuts, together with their common names. 3. `reply-safety-check.csv` with columns: `review_ref`, `trigger`, `text_found_verbatim`, `position`, `rule_cited_verbatim`, `rule_source_url`, `verdict`. `trigger` is exactly one of `threat of legal action`, `mention of solicitor police or defamation`, `demand to remove the review`, `accusation that the review is fake`, `refund voucher or compensation`, `offer conditional on the review changing`, `reviewer name`, `room or table number`, `date of visit`, `booking reference`, `order detail`, `contact detail`, `named staff member`, `over the word limit`, `no signature`. `verdict` is `pass` or `must not be posted`. Every `must not be posted` row is listed in `gaps.md` before anything else. 4. `records-support.csv` with columns: `review_ref`, `claim_in_review_verbatim`, `reply_sentence_verbatim`, `records_position`, `records_system`, `records_line`. `records_position` is exactly one of `records confirm`, `records contradict`, `records silent`. Any reply sentence that apologises for a claim where `records_position` is `records contradict`, or that denies a claim where it is `records confirm`, is listed in `gaps.md`. 5. `offline-actions.csv` with columns: `review_ref`, `action`, `owner`, `due_date`, `done_date`, `mentions_the_review`. `mentions_the_review` is `yes` or `no` and must be `no` for every row. Any `yes` row is listed in `gaps.md`. 6. `reply-log.csv` with columns: `date`, `platform`, `review_ref`, `rating`, `sort`, `reply_text_verbatim`, `signed_as`, `signer_read_it`, `incident_ref`, `offline_action_count`, `reported_to_platform`, `extortion_reported`. Appended to any previous log, never overwritten. 7. `gaps.md` - a numbered list of: every `must not be posted` verdict; every review mentioning an allergen, illness, injury or discrimination with no incident reference; every reply sentence contradicted by the records; every offline action that mentions the review; every reply not read by the person it is signed as; every review sorted as a policy violation that also has a draft reply; and any review carrying a demand for payment with no record that it was reported. ## Rules - Codex sorts nothing, writes nothing and softens nothing. It searches, matches, cites and records. The sort, the reply and the decision to report all arrive with the input. - Never draft, rewrite, shorten or tone down a reply. Where a reply fails the safety check, record every failing element verbatim with its position and the rule it breaks, and mark the reply `must not be posted`. The owner rewrites it. - Never write a legal threat, a takedown demand, an accusation that a review is false, or an offer of any kind into any file, including as an example. - Never mark a reply sentence as supported unless a line of the supplied records table says so, naming the system it came from. `records silent` is a legitimate and common answer and is recorded as such, never upgraded. - Never copy a reviewer's name, contact detail, room or table number, booking reference or order into any file other than `trigger-words.csv` and `reply-safety-check.csv`, where it exists only to be flagged for removal. - Never write a recovery rate, a percentage of reviews updated after a reply, an industry benchmark or any figure about what answering complaints is worth. No such figure exists for a single independent UK venue. - Positions, word counts and character counts are counted, never estimated. Word searches are literal and case insensitive and record every hit with its position. - Every quoted review, reply, rule and record line is copied exactly, including punctuation, capitalisation and any emoji. - Never post anything, never connect to a platform's management centre or API, never report a review, and never contact a reviewer. - Use British English, GBP and DD Month YYYY dates. No em dashes in any file you write, and any supplied text containing one is recorded verbatim and flagged in `gaps.md`. - Every file ends with this line: this is a working document prepared for the owner to check against their own records before posting, and for their solicitor, insurer, HR adviser or environmental health officer to check anything alleging illness, injury, discrimination or a legal wrong. It applies supplied rules to draft copy and is not legal advice. ## Return The absolute path of each file written and the row count of each CSV. The count of reviews by sort, and the count by `reply_required`. Every allergen, illness, injury and discrimination trigger found, with the review reference, the exact words and whether an incident reference exists. Every `reply-safety-check.csv` row with a `must not be posted` verdict, quoted in full with its rule and source URL. Every reply sentence whose records position is `records contradict` or `records silent`, with the sentence and the records line. The word count of each reply and any over one hundred words. The number of replies not read by their signer. Every offline action that mentions the review. Every demand for payment found, with whether it was reported. The new `reply-log.csv` rows exactly as written, and the `gaps.md` item count.
Built from the best public work on this
Sources for one-star-reply
Everything below was opened and read on 16 September 2026. Nothing is cited that could not be loaded.
1. Competition and Markets Authority, "Fake reviews" (CMA208)
https://assets.publishing.service.gov.uk/media/67eeb64fe9c76fa33048c790/CMA208_-_Fake_reviews_guidance.pdf, published 4 April 2025, read 16 September 2026.
Most of this guidance is about reviews a trader causes to exist. One paragraph is about reviews a trader wishes did not exist, and it is the reason two of this skill's steps are refusals rather than techniques.
Paragraph 4.4 opens with a distinction worth keeping: "While it is important to suppress fake negative reviews, suppressing genuine negative reviews is problematic." It then lists what a trader must not do. Traders should not "interfere with the ability and willingness of reviewers to leave negative reviews in the first place such as: (i) through threats of harm or legal action, (ii) by preventing bona fide users from leaving reviews, (iii) by arbitrarily stopping and starting review invitations, (iv) by making an offer of dispute resolution contingent on a consumer not leaving a negative review etc." and should not "limit access to and/or the impact of negative reviews by editing, withholding or removing such reviews".
Limb (i) is step 4. Limb (iv) is step 6, and it is the one that catches decent owners, because putting a bad meal right is exactly what a good publican does. The guidance does not say you may not fix it. It says you may not make the fixing conditional on the review.
Chapter 3's examples sharpen the same point. Among the practices listed as commissioning banned reviews is "Contacting a customer who has left a negative review and offering them a refund and/or a gift card if they change their review to remove the negative commentary (so that it is no longer reflective of their genuine experience)." The parenthesis is the legal hinge: a changed review that no longer reflects the reviewer's experience is a fake review, and the person who asked for the change commissioned it.
Where the skill departs: this is guidance on a banned practice, addressed to traders generally and heavy on platform obligations. The skill takes only paragraphs 4.3 to 4.5 and the Chapter 3 examples, and does not attempt to explain the enforcement regime to somebody who has ten minutes and a furious review on their phone.
2. Tripadvisor, "Management Response Guidelines"
https://www.tripadvisor.co.uk/Trust-lpgT1CmsfQ3E.html, no publication date shown on the page, read 16 September 2026.
Short, blunt and the most practically useful document in this set, because it tells an owner exactly which instincts will get the response rejected.
Under "Relevant": "Management responses may not threaten or coerce a reviewer or attempt to suppress reviewer contributions on our site. No accusations of review fraud. No responses directed to Tripadvisor staff or commenting about Tripadvisor policies." Three separate reflexes, all banned in one line: threatening them, calling the review fake, and arguing with Tripadvisor in public.
Under "Respectful of Privacy": "No speculation as to the identity of the reviewer. Personal information that may be used to identify an individual is prohibited, including but not limited to names, addresses, and phone numbers." That rules out the most common defensive move, which is proving in public that you know exactly who this is and what they ordered.
Under "Original": "Please do not include correspondence from guests or third parties, or snippets of traveler reviews", which rules out pasting in the email where the guest said something different at the time.
Where the skill departs: the guidelines also cover responses to media notifications on a listing, which is a press incident rather than a review, and the formatting rules for those. The skill leaves both alone and points serious incidents at people with the right training.
3. Tripadvisor, "Trust and safety review posting guidelines"
https://www.tripadvisor.co.uk/Trust-lvBd3L1aU38Y.html, no publication date shown on the page, read 16 September 2026.
Used for step 9, and for two of the prohibitions in step 6. On removals: "Attempts by an individual representing a property to offer anything in exchange for the removal of a published review are against our guidelines and will be met with penalties", and separately, "Attempts by anyone affiliated with a property to pressure, threaten or otherwise coerce a user into removing their review for that property are a violation of our guidelines".
The blackmail definition is the valuable part, because it is carefully bounded in both directions: "Tripadvisor classifies any attempt made in bad faith by a traveller to obtain something of value from a property by threatening to post a negative review on Tripadvisor or promising to remove a published negative review, as blackmail. It is not considered blackmail if a guest mentions that they plan to write a review due to a negative experience but is not making a bad faith demand. Examples would include a guest trying to rectify a situation with a broken pipe in a room or an incorrect order at a restaurant."
That second half matters more than the first. A guest saying they will be leaving a review is not blackmail, it is a guest, and an owner who treats it as extortion behaves badly on the strength of a misunderstanding.
Where the skill departs: the page's long sections on what makes a review ineligible, on bias and on review bombing decide whether a review can be reported. That is the fake-review-takedown skill's job, and mixing it into a reply is exactly the error step 5 guards against.
4. Google, "Tips to get more reviews", Google Business Profile Help
https://support.google.com/business/answer/3474122, no publication date shown on the page, read 16 September 2026.
The section headed "Give helpful responses to negative reviews" is the only piece of official platform advice we could find on how to write this particular reply, and four of its lines are used directly.
"Protect privacy and avoid personal attacks: Never share the reviewer's private info. Do not attack them personally. This applies on Maps, other services or in person. You can request the reviewer to contact you, in person, email or phone to help resolve the issue." The clause "or in person" is the one worth reading twice, in step 8.
"Find out why the reviewer had a negative experience: Check your records about the reviewer and their visit." That is step 3, and the skill adds the constraint Google does not state: check them, then keep them out of the reply.
"Be honest and explain limitations: Admit mistakes that were made, but don't take responsibility for things outside your control." That is the core of step 7, and it is a better instruction than the blanket apology most templates produce.
The page also opens the negative section by pointing at the reporting route: "You can flag a review if you believe that it violates Google's content policies", which is where step 1's third category goes.
Where the skill departs: Google also advises replying "in a timely manner". The skill deliberately overrides that with a rule about not replying in the same hour. Nothing in any published rule requires speed, and the replies that cost venues the most are the fast ones.
5. Defamation Act 2013, sections 1, 2 and 3
https://www.legislation.gov.uk/ukpga/2013/26/section/1/enacted, https://www.legislation.gov.uk/ukpga/2013/26/section/2/enacted and https://www.legislation.gov.uk/ukpga/2013/26/section/3/enacted, Act of Parliament 2013, read 16 September 2026.
Cited for one purpose: so that step 4 can explain why the legal threat is empty rather than simply forbidding it. An owner who is only told not to threaten will threaten anyway at two in the morning.
Section 1(1): "A statement is not defamatory unless its publication has caused or is likely to cause serious harm to the reputation of the claimant." Section 1(2) raises the bar again for a business: "For the purposes of this section, harm to the reputation of a body that trades for profit is not 'serious harm' unless it has caused or is likely to cause the body serious financial loss."
Section 2(1) is the truth defence: "It is a defence to an action for defamation for the defendant to show that the imputation conveyed by the statement complained of is substantially true." Section 3 is honest opinion, and its three conditions are that the statement "was a statement of opinion", that it "indicated, whether in general or specific terms, the basis of the opinion", and that "an honest person could have held the opinion" on the basis of any fact existing at the time. Section 3(8) records that "The common law defence of fair comment is abolished".
A one star review saying the service was slow and the risotto was cold is opinion with its basis stated, is probably substantially true in part, and would require the venue to evidence serious financial loss. That is three walls before you reach a solicitor's first letter.
Where the skill departs: the skill takes no view on whether any particular review is defamatory, because that is a solicitor's judgement on facts nobody here has. It uses these sections to describe the shape of the hurdle and stops. Where a review genuinely alleges something false and damaging, the answer is proper advice and, separately, the notice of complaint route under section 5, which belongs to the fake-review-takedown skill.
6. Food Standards Agency, "Allergen guidance for food businesses"
https://www.gov.uk/government/publications/allergen-guidance-for-food-businesses/allergen-guidance-for-food-businesses, updated 17 July 2026, no separate first publication date shown on the guidance page, read 16 September 2026.
In this skill for one reason: to stop a reply being written at all where the review describes an allergic reaction. The guidance sets the duty for what a restaurant serves: "If you provide non-prepacked foods, you must supply allergen information for every item that contains any of the 14 allergens", and confirms these requirements "can apply to loose items sold at a delicatessen counter, a bakery, a butcher's, as well as meals served in a restaurant, and food from a takeaway."
Information may be given by "full written allergen information on a menu, chalkboard or in an information pack" or "verbally, with a written notice placed in a clearly visible position explaining how your customers can obtain this information". The FSA's own preference is stated: "Our advice to food businesses providing non-prepacked food is that written allergen information, supported by a conversation, works best for consumers."
The fourteen are named in full on the page: celery, cereals containing gluten, crustaceans, eggs, fish, lupin, milk, molluscs, mustard, peanuts, sesame, soybeans, sulphur dioxide and sulphites above ten parts per million, and tree nuts. Those words are what the search in the Codex brief looks for, because a review that names one of them is describing your allergen process in public.
Where the skill departs: the guidance covers labelling, free-from claims, precautionary allergen labelling and staff training in detail. None of that is taught here. The skill uses the page for a single trigger: if these words appear in a review, this is an incident before it is a reply, and it belongs with the people who handle incidents.
7. Google, "Prohibited and restricted content", Maps User Contributed Content Policy, and "Report inappropriate reviews on your Business Profile"
https://support.google.com/contributionpolicy/answer/7400114 and https://support.google.com/business/answer/4596773, no publication dates shown on either page, read 16 September 2026.
Two narrow uses. The content policy's "Offensive content" section prohibits "Unsubstantiated allegations of unethical behaviour or criminal wrongdoing" and allows "content that describes negative experiences in a respectful manner". The first half is a fair description of a public reply that calls a reviewer a liar, which is step 5. The "Personal information" section provides the rule in step 8, and draws the line an owner needs: the policy expressly does allow merchants "to post contact information related to their business", so yours is fine and theirs is not.
The reporting page supplies step 9's separate route: "If your Business Profile has been targeted by an extortion scam involving negative reviews, learn how to report the incident." It also states plainly what the skill repeats in its rules: "Do not report a review just because you disagree with it or dislike it. Google doesn't get involved in conflict between businesses and customers."
Where the skill departs: the reporting page's full mechanics, the Reviews Management Tool, the one time appeal and the escalation statuses, are set out in the fake-review-takedown skill. Here it is only a signpost, because the moment a reply turns into a report the two documents must stop being the same document.
Best public prompt we found for this job
The best public artefact is the `customer-escalation` skill in Anthropic's `knowledge-work-plugins` repository, raw source at https://raw.githubusercontent.com/anthropics/knowledge-work-plugins/main/customer-support/skills/customer-escalation/SKILL.md. The repository has 24,123 stars, read from api.github.com on 16 September 2026. It is not a review skill. It is a triage skill, and triage is the part of this job that owners skip.
The idea we took is its first move, before any writing happens:
Use the "When to Escalate vs. Handle in Support" criteria below to confirm this warrants escalation.
That is step 1 here. A one star review is not one kind of thing, and sorting it before drafting is what separates a reply that closes the matter from a reply that becomes evidence in a food safety investigation. Its impact dimensions, breadth, depth, duration, revenue and time pressure, also informed the decision to route allergen and injury reviews out of the reply process entirely rather than handling them with a more carefully worded reply.
We did not copy three things. It is written for an internal audience, so its brief is candid in a way a public reply can never be; here the internal note and the public reply are deliberately different documents with different rules, and the check list exists to stop the first leaking into the second. It assumes a support platform holds the history; a venue has a booking system, a till and somebody's memory, so step 3 asks for a records table with a named system per line and treats "records silent" as a real answer. And it has no adversary. In a support queue nobody is trying to make the company look bad. Under a one star review the reply is read by strangers deciding where to eat, and the tone that works on a ticket, thorough and explanatory, reads on a public page as an argument the venue is losing.
Want this running in your business?
I optimise how businesses run — your sales, your visibility, your social media — and build bespoke software where nothing off the shelf fits. The first conversation is free. Work starts from £150 a day.
Foxera