gtm-setup
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill serves as a legitimate reference for Google Tag Manager (GTM) setup and configuration.- [DATA_EXFILTRATION]: No evidence of unauthorized data access or exfiltration. All external links point to trusted domains, including official Google documentation and the author's own domain (cogny.com).- [PROMPT_INJECTION]: The instructions provide standard framing for the agent to act as a GTM expert. There are no attempts to bypass safety filters, extract system prompts, or override agent constraints.- [INDIRECT_PROMPT_INJECTION]: The skill presents a minimal attack surface common to reference assistants. While it processes user-provided topics, the functionality is centered on providing documentation snippets and using official GTM tools.
- Ingestion points: User-provided topics or questions passed as arguments to the skill.
- Boundary markers: Absent.
- Capability inventory: File system access (Read/Write), shell execution (Bash), network access (WebFetch/WebSearch), and vendor-specific GTM MCP tools.
- Sanitization: None explicitly defined in the instructions.- [EXTERNAL_DOWNLOADS]: The skill does not perform any remote code downloads or package installations. It contains only static reference material and JavaScript code templates intended for user implementation.
Audit Metadata