google-analytics-data-api-basics
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- Indirect Prompt Injection Surface: The skill is designed to ingest and process reporting data from the Google Analytics API, as seen in
SKILL.mdand various language-specific guides in thereferences/directory. Because this content originates from an external source, it represents a standard data ingestion surface common to analytics tools. - Ingestion points: Data is retrieved via
client.run_reportor equivalent methods inSKILL.md,references/python.md,references/nodejs.md,references/php.md,references/go.md,references/ruby.md,references/dotnet.md, andreferences/java.md. - Boundary markers: The provided code snippets do not include explicit prompt boundary markers or instructions to ignore embedded commands within the retrieved data.
- Capability inventory: The skill demonstrates capabilities for system configuration via the Google Cloud CLI, package installation, and performing network requests to API endpoints.
- Sanitization: The example code performs direct output of retrieved dimensions and metrics without additional sanitization layers, which is standard for demonstration purposes.
- External Dependency Management: The skill provides instructions for installing official client libraries, such as
google-analytics-datafor Python and@google-analytics/datafor Node.js. These are vendor-maintained packages required for the skill to communicate with the Google Analytics service. - System Configuration Commands: The instructions include the use of the Google Cloud CLI (
gcloud) to enable services and configure Application Default Credentials (ADC). These commands are standard administrative tasks for setting up a development environment to interact with Google Cloud services.
Audit Metadata