pp-google-tag-manager
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
google-tag-manager-pp-cliand an MCP server usingnpxandgo installfrom the vendor's repositories. - Evidence:
npx -y @mvanhorn/printing-press-library install google-tag-manager --cli-onlyandgo install github.com/mvanhorn/printing-press-library/library/marketing/google-tag-manager/cmd/google-tag-manager-pp-mcp@latest. - [DATA_EXFILTRATION]: The skill provides a
--deliver webhook:<url>flag that allows the agent to POST command output to an arbitrary URL, which is a potential exfiltration vector. - Evidence: Description of the
webhook:<url>sink in the Output Delivery section. - [DATA_EXFILTRATION]: An optional feedback mechanism can be configured to automatically send local data to a remote endpoint.
- Evidence:
GOOGLE_TAG_MANAGER_FEEDBACK_ENDPOINTandGOOGLE_TAG_MANAGER_FEEDBACK_AUTO_SENDenvironment variables. - [INDIRECT_PROMPT_INJECTION]: The skill mirrors external GTM container configuration into a local database for processing, which presents a surface for indirect prompt injection.
- Ingestion points: GTM container data is ingested via the
pullcommand. - Boundary markers: None identified in the skill instructions.
- Capability inventory: The skill uses the
Bashtool to execute the CLI, writes to a local SQLite database, and can perform network POST requests via webhooks. - Sanitization: No specific sanitization or validation of the GTM container content is mentioned.
Audit Metadata