analytics-tracking-automation
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent to clone code from a third-party GitHub repository (
jtrackingai/analytics-tracking-automation) and usenpxto install and run remote packages that are not from a pre-verified trusted organization. - [COMMAND_EXECUTION]: The skill requires the execution of multiple shell commands to set up the environment (
git clone,npm install,npm run install:skills) and to perform analytics tasks using a custom CLI tool (npx event-tracking). - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external websites which could be manipulated to influence the agent's behavior.
- Ingestion points: The
analyzeSitefunction andinitcommand crawl external website URLs provided at runtime (SKILL.md). - Boundary markers: The workflow includes a "manual checkpoint" and a "Schema review checkpoint" where users are encouraged to review the generated plan before it is synced to Google Tag Manager (SKILL.md).
- Capability inventory: The skill has the ability to write files (artifact creation), perform network operations (Google Tag Manager API calls), and execute browser automation (Playwright-based verification).
- Sanitization: No explicit sanitization or escaping of the content crawled from external sites is mentioned before it is processed into event schemas.
- [CREDENTIALS_UNSAFE]: The skill handles sensitive Google OAuth
CLIENT_IDandCLIENT_SECRETvia environment variables and caches authentication tokens in a local file (oauth-tokens.json) within the project's artifact directory, which could lead to credential exposure if the directory is not properly secured.
Audit Metadata