gtm-tracking-setup

Pass

Audited by Gen Agent Trust Hub on Apr 25, 2026

Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and includes configurations for community templates and tracking scripts from well-known and trusted providers including Microsoft Clarity, Google Analytics, LinkedIn, and Reddit. These external resources are standard for analytics and are used according to vendor guidelines.
  • [PROMPT_INJECTION]: The skill incorporates a workflow step to read and analyze project source code (e.g., under dev/ or apps/) to inform tracking design. This ingestion of untrusted local data represents an indirect prompt injection surface; however, this is a necessary part of the skill's primary function and does not involve the execution of untrusted code by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 25, 2026, 09:01 PM
Security Audit — agent-trust-hub — gtm-tracking-setup