gtm-tracking-setup

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and platform-specific manuals consistently prioritize user data privacy, explicitly warning against the transmission of Personally Identifiable Information (PII) like email addresses, phone numbers, or clear-text names to tracking vendors.
  • [SAFE]: All GTM container examples use templated placeholders (e.g., {ACCOUNT_ID}, {GA4_MEASUREMENT_ID}) for sensitive identifiers, ensuring no actual credentials or account keys are hardcoded in the skill resources.
  • [SAFE]: External script references in the generated configurations (for services like Microsoft Clarity, Hotjar, and Bing) point to the official domains of well-known technology providers, and the instructions for their implementation include security-conscious practices such as data sanitization and script isolation.
  • [SAFE]: The skill's primary behavior of reading workspace source code to improve tracking precision is a legitimate development-oriented function and is limited to identifying HTML structures for trigger conditions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 04:16 PM
Security Audit — agent-trust-hub — gtm-tracking-setup