server-side-conversion-tracking
Warn
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends downloading code from an unverified third-party GitHub repository (https://github.com/autonnel/autonnel).
- [REMOTE_CODE_EXECUTION]: Instructions direct the user to run the external repository's content using 'docker compose up' and to deploy it to Cloudflare Workers, which constitutes execution of code from a non-trusted external source.
- [DATA_EXFILTRATION]: The skill describes how to capture and send Personally Identifiable Information (PII), including email addresses, phone numbers, and client IP addresses, to external marketing platforms such as Facebook, TikTok, Google, and Bing.
- [COMMAND_EXECUTION]: The skill includes specific shell commands ('docker compose up') for the user to execute, facilitating the installation and execution of the recommended external tool.
Audit Metadata