server-side-tracking
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a data ingestion surface that processes external tracking events and routes them to third-party services.
- Ingestion points: The
collect_eventfunction inscripts/process.pyingests untrusted JSON payloads via a POST endpoint. - Boundary markers: The skill relies on structured JSON processing but does not implement specific delimiters to prevent command or prompt injection within data fields.
- Capability inventory: The skill has the capability to perform outbound network requests via the
requestslibrary to external API endpoints as seen inforward_to_ga4andforward_to_meta_capifunctions. - Sanitization: The script implements robust sanitization measures, including IP anonymization (zeroing octets/bits in
anonymize_ip), SHA-256 hashing for PII (email inhash_pii), and URL minimization (stripping query parameters inminimize_url) before any data transmission to third parties occurs. - [EXTERNAL_DOWNLOADS]: The skill references standard third-party libraries required for its execution environment.
- Python packages: The implementation requires
flaskandrequests, which are widely recognized and standard for building web services and handling HTTP requests. - [SAFE]: The skill's implementation aligns with its stated purpose of improving privacy and security in tracking workflows.
- Network operations are limited to well-known analytics and advertising domains (Google and Meta) which are considered standard for this use-case context.
- Sensitive credentials like API secrets and access tokens are retrieved from environment variables in
scripts/process.pyrather than being hardcoded in the scripts. - The Python script uses standard, reputable libraries for its functionality and incorporates data minimization principles throughout the event routing process.
Audit Metadata