analytics-tracking

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices by using placeholders (e.g., G-XXXXXXXX, YOUR_PIXEL_ID) instead of hardcoded credentials.
  • [DATA_EXPOSURE]: Includes explicit instructions to avoid collecting Personally Identifiable Information (PII) and emphasizes compliance with privacy regulations like GDPR.
  • [PROMPT_INJECTION]: No malicious injection patterns or attempts to bypass system constraints were detected in the instructions or metadata.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads context from '.agents/product-marketing-context.md'. While this is an external ingestion point, the context is used only to inform analytics strategy recommendations and does not trigger any high-risk capabilities like system commands or file writes.
  • [COMMAND_EXECUTION]: The skill does not contain any shell commands, subprocess calls, or dynamic code execution patterns. Code snippets provided are standard JavaScript templates for web analytics implementation (gtag.js and dataLayer.push).
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 11:47 PM
Security Audit — agent-trust-hub — analytics-tracking