skills/ssheleg/sheleg-dev/ad-tracking/Gen Agent Trust Hub

ad-tracking

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides integration instructions and local verification scripts that adhere to security best practices. No malicious patterns such as prompt injection, obfuscation, or persistence mechanisms were found.
  • [EXTERNAL_DOWNLOADS]: The skill documentation references official script loading from well-known service providers (Google Tag Manager and Meta). These references are standard for the stated purpose and target official, trusted domains.
  • [DATA_EXFILTRATION]: The skill correctly identifies PII (email, phone number) as sensitive and instructs users to hash this data using SHA-256 before transmission. All provided test fixtures use synthetic placeholder data to prevent accidental exposure of real credentials.
  • [COMMAND_EXECUTION]: Local Node.js scripts are provided for validating purchase event deduplication logic. These scripts operate solely on local JSON fixtures and do not perform network requests or execute unauthorized system commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:58 AM
Security Audit — agent-trust-hub — ad-tracking