analytics-tracking-automation

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent to clone code from a third-party GitHub repository (jtrackingai/analytics-tracking-automation) and use npx to install and run remote packages that are not from a pre-verified trusted organization.
  • [COMMAND_EXECUTION]: The skill requires the execution of multiple shell commands to set up the environment (git clone, npm install, npm run install:skills) and to perform analytics tasks using a custom CLI tool (npx event-tracking).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external websites which could be manipulated to influence the agent's behavior.
  • Ingestion points: The analyzeSite function and init command crawl external website URLs provided at runtime (SKILL.md).
  • Boundary markers: The workflow includes a "manual checkpoint" and a "Schema review checkpoint" where users are encouraged to review the generated plan before it is synced to Google Tag Manager (SKILL.md).
  • Capability inventory: The skill has the ability to write files (artifact creation), perform network operations (Google Tag Manager API calls), and execute browser automation (Playwright-based verification).
  • Sanitization: No explicit sanitization or escaping of the content crawled from external sites is mentioned before it is processed into event schemas.
  • [CREDENTIALS_UNSAFE]: The skill handles sensitive Google OAuth CLIENT_ID and CLIENT_SECRET via environment variables and caches authentication tokens in a local file (oauth-tokens.json) within the project's artifact directory, which could lead to credential exposure if the directory is not properly secured.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — analytics-tracking-automation