pp-google-analytics

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of a CLI tool from the author's NPM package (@mvanhorn/printing-press-library) or GitHub repository. These sources are consistent with the skill's authorship.
  • [COMMAND_EXECUTION]: The skill relies on executing the google-analytics-pp-cli binary to interact with Google Analytics data. It uses environment variables for authentication, which is a standard and safe practice for this type of tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface through Google Analytics reports. 1. Ingestion points: GA4 API data processed by the CLI tool. 2. Boundary markers: None explicitly mentioned in the instructions. 3. Capability inventory: Command execution via the CLI tool to process reports. 4. Sanitization: Relies on the standard Google API and CLI implementation. This is a common attack surface for data-processing skills but shows no evidence of malicious exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 08:16 AM
Security Audit — agent-trust-hub — pp-google-analytics