website-health-analytics
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates data collection by executing commands through
execFileSyncin its utility scripts. It interacts with the GitHub CLI (gh), Firebase CLI (firebase), and companion tools. These calls are performed using array-based arguments without a shell, which prevents command injection vulnerabilities. - [EXTERNAL_DOWNLOADS]: The skill documentation instructs users to install two companion skills from a third-party GitHub repository (
Bin-Huang/google-analytics-cliandBin-Huang/google-search-console-cli). These are functional dependencies required for data fetching. - [DATA_EXPOSURE]: The skill processes potentially sensitive data, including Firebase user exports which contain email addresses. The documentation explicitly identifies this as PII (Personally Identifiable Information) and directs users to maintain all raw data in a gitignored working directory (
.claude/wha-work/) to prevent accidental data leakage. - [CREDENTIALS_UNSAFE]: To access Google APIs, the skill requires a service account JSON key. It mitigates credential theft risks by instructing users to provide only the local file path to the key in a gitignored configuration file (
.claude/website-health-analytics.local.json) rather than embedding the secret itself. - [PROMPT_INJECTION]: Due to its primary function of ingesting and analyzing data from external sources (Search Console queries, GitHub PR titles/descriptions, and Analytics metadata), the skill has an indirect prompt injection surface. While the scripts perform deterministic processing, the agent's final interpretation of findings could be influenced by malicious content embedded in those external data sources.
Audit Metadata