google-tag-manager
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze Google Tag Manager container exports in JSON format. This represents an indirect prompt injection surface where a malicious actor could embed instructions within tag names or triggers in a container to influence the agent's audit report.
- Ingestion points: Processes GTM container JSON exports provided by the user (SKILL.md, EXAMPLES.md).
- Boundary markers: The skill does not specify explicit delimiters or "ignore embedded instructions" warnings for the untrusted container data.
- Capability inventory: The skill is primarily instructional but mentions a related
gtm-implementeragent for writing changes via API. - Sanitization: No specific sanitization or validation of the input JSON structure or content is described.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download its source code and other marketing skills from a remote repository.
- Evidence:
git clone https://github.com/thatrebeccarae/claude-marketing.git(SKILL.md). - Context: The repository belongs to the skill's author, representing a legitimate vendor resource.
- [METADATA_POISONING]: The skill includes futuristic dates in its metadata and reference materials which could be misleading.
- Evidence:
updated: 2026-03-18in SKILL.md and references to TCF v2.3 compliance as of February 2026 in REFERENCE.md. - Context: While likely a stylistic choice or error, inaccurate metadata is technically deceptive.
Audit Metadata