analytics-tracking

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data sources, including analytics event logs and marketing URLs, through its included Python utility scripts. This creates a potential surface where malicious instructions embedded in the data could influence the agent's behavior during analysis.
  • Ingestion points: scripts/event_schema_checker.py (JSON event files), scripts/utm_validator.py (CSV files and URL strings), and scripts/funnel_drop_off_analyzer.py (JSON and stage strings).
  • Boundary markers: No specific delimiters or "ignore instructions" wrappers are prescribed in SKILL.md for the processing of these external inputs.
  • Capability inventory: A technical review of all provided scripts confirmed they perform pure data parsing and validation; there is no evidence of subprocess execution, network operations, or file system writing capabilities that could be exploited.
  • Sanitization: The scripts use native Python library parsers (json, csv, urllib.parse) to process data, which provides standard protection against basic malformed input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 06:47 PM
Security Audit — agent-trust-hub — analytics-tracking