analytics

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires access to powerful system tools including bash, run_command, write_to_file, and replace_file_content. These tools are leveraged to verify tracking implementations on live sites, run audits, and modify project source code to insert analytics tags as described in SKILL.md and references/tracking.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill performs detailed audits of external website funnels, session recordings, and user commitment paths, creating an ingestion point for potentially untrusted data that could influence agent behavior.
  • Ingestion points: External website HTML, signup funnel field data, and session replay recordings analyzed in references/cro.md and references/tracking.md.
  • Boundary markers: The procedures do not define explicit delimiters or instructions to ignore embedded prompts when analyzing data from external site audits.
  • Capability inventory: The agent has bash, run_command, and broad file system write access across all modes.
  • Sanitization: No specific sanitization or filtering is mentioned for content ingested from audited web pages before it is processed by the agent logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:22 PM
Security Audit — agent-trust-hub — analytics