gtm-monitor

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate monitoring and auditing of Google Tag Manager (GTM) containers as per its described purpose.- [DATA_EXPOSURE]: The skill accesses GTM configuration data including tags, triggers, and variables. This access is performed through specialized tools provided by the vendor (Cogny AI) and is necessary for the skill's monitoring functionality.- [COMMAND_EXECUTION]: The skill uses a set of predefined tools to interact with the GTM API and manage its internal state. These tools are used appropriately within the scope of the monitoring workflow.- [INDIRECT_PROMPT_INJECTION]:- Ingestion points: Data is ingested from the external Google Tag Manager environment (tags, triggers, and variable configurations) in Step 2 of SKILL.md.- Boundary markers: The instructions do not specify any explicit boundary markers or delimiters for the data retrieved from the GTM container.- Capability inventory: The skill possesses the ability to store data locally via 'write_context_node' and report issues via 'create_finding'.- Sanitization: There are no explicit sanitization steps mentioned for the data retrieved from GTM before it is processed or reported.
  • Note: The overall risk is low as the ingested data is primarily used for comparison and reporting within a controlled vendor ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 11:31 AM
Security Audit — agent-trust-hub — gtm-monitor