Back to skill

Security audit

Google Analytics 4 Analytics

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent GA4 analytics purpose, but it tells the agent to run an unbundled absolute-path executable that would receive Google Analytics credential access.

Review this before installing. Only use it if you already trust the exact ga4-analytics executable at that path, can verify its integrity, and provide a least-privilege read-only Google service account limited to the intended GA4 property. Prefer a package that includes auditable source or a pinned, hash-checked binary.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:14
Finding

Execution of an Unreviewable External Binary with Access to Sensitive Credentials

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description and the entire usage guidance are written exclusively in German, including directive phrases for when to use the skill. This creates a natural-language locale constraint without any opt-in or documented justification that the skill is intentionally German-only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.