google-analytics-data-api-basics

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to ingest and process reporting data from the Google Analytics API, as seen in SKILL.md and various language-specific guides in the references/ directory. Because this content originates from an external source, it represents a standard data ingestion surface common to analytics tools.
  • Ingestion points: Data is retrieved via client.run_report or equivalent methods in SKILL.md, references/python.md, references/nodejs.md, references/php.md, references/go.md, references/ruby.md, references/dotnet.md, and references/java.md.
  • Boundary markers: The provided code snippets do not include explicit prompt boundary markers or instructions to ignore embedded commands within the retrieved data.
  • Capability inventory: The skill demonstrates capabilities for system configuration via the Google Cloud CLI, package installation, and performing network requests to API endpoints.
  • Sanitization: The example code performs direct output of retrieved dimensions and metrics without additional sanitization layers, which is standard for demonstration purposes.
  • External Dependency Management: The skill provides instructions for installing official client libraries, such as google-analytics-data for Python and @google-analytics/data for Node.js. These are vendor-maintained packages required for the skill to communicate with the Google Analytics service.
  • System Configuration Commands: The instructions include the use of the Google Cloud CLI (gcloud) to enable services and configure Application Default Credentials (ADC). These commands are standard administrative tasks for setting up a development environment to interact with Google Cloud services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 04:45 PM
Security Audit — agent-trust-hub — google-analytics-data-api-basics