tracking-architect

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to process external, potentially untrusted documents such as event registries and tracking contracts to guide the generation of analytics code and SQL queries.\n
  • Ingestion points: The agent is instructed in SKILL.md to read an event registry and tracking contract from the project environment.\n
  • Boundary markers: No explicit instruction delimiters or ignore blocks are defined for the ingested data files.\n
  • Capability inventory: The skill generates executable SQL (scripts/funnel_dropoff_analysis.sql) and TypeScript code (templates/tracking-schema.ts).\n
  • Sanitization: The skill provides explicit PII auditing rules in templates/tracking_audit_checklist.md and implements schema validation using Zod in its templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:13 PM
Security Audit — agent-trust-hub — tracking-architect