Back to skill

Security audit

Analytics & Tracking Setup

Security checks for vulnerabilities and agentic risk

Overview

This analytics skill is not malicious, but it needs review because its stated Segment tracking behavior does not match the shipped files and its examples include personal data without clear consent guidance.

Review before installing or using this skill. Treat the Segment examples as under-specified and avoid sending names, emails, user IDs, or traits unless you have a lawful basis, consent, and a clear data-processing plan. If using the pixel snippets, gate Meta and Google tracking behind a consent banner and update the privacy policy first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose says the skill tracks events and user behavior using Segment, which implies analytics/event collection and likely communication with Segment APIs or SDKs. The actual code does none of that: it only parses a URL and appends UTM parameters for marketing attribution. There is no event tracking, user behavior collection, Segment library usage, network access, or analytics integration. This is a material mismatch in primary purpose and functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The examples include personal data such as name, email, user IDs, and organization traits, but the documentation does not warn that this information would be sent to a third-party analytics provider. This creates a meaningful privacy and compliance risk because users may transmit PII without informed consent, data minimization, or understanding of retention and sharing implications.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · TRACKING-PLAN.md (reported line 66)May include surrounding context.

Facebook Pixel

html
<!-- Facebook Pixel Code -->
<script>
!function(f,b,e,v,n,t,s)
{if(f.fbq)return;n=f.fbq=function(){n.callMethod?

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · TRACKING-PLAN.md (reported line 66)May include surrounding context.

Facebook Pixel

html
<!-- Facebook Pixel Code -->
<script>
!function(fbevnts)
{if(f.fbq)return;n=f.fbq=function(){n.callMethod?

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README promotes deployment of conversion tracking pixels and attribution tracking without any mention of consent, privacy compliance, or user-notice requirements. In a marketing analytics skill, this omission can lead operators to implement user tracking in ways that violate privacy laws, internal policy, or user expectations, especially because the content emphasizes quick copy-paste deployment.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill metadata declares no tool scope or permissions, yet the skill's stated purpose and examples imply outbound communication to Segment, a third-party analytics service. Missing explicit network/tool scoping weakens reviewability and consent controls, making unintended or opaque data egress more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares no trigger patterns and provides no invocation constraints, despite enabling analytics actions that may transmit user identifiers and traits externally. Broad or ambiguous activation conditions increase the chance the skill is invoked in inappropriate contexts, causing accidental collection or disclosure of personal data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This plan explicitly includes third-party analytics and advertising pixels that collect behavioral data, and the implementation examples place tracking code directly on the site. Although the document later mentions cookie banners and opt-in telemetry, the point-of-use sections do not clearly gate GA4/Meta Pixel behind consent or describe region-specific compliance requirements, which can lead to unlawful or privacy-invasive deployment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · TRACKING-PLAN.md (reported line 180)May include surrounding context.

md
- [ ] Configure Gumroad webhook endpoint
- [ ] Build UTM link generator script (utm_builder.py) ✅
- [ ] Document pixel configs (pixel_configs.json) ✅
- [ ] Create attribution rules (attribution_config.json) ✅
- [ ] Add UTM parameters to all external links
- [ ] Test conversion tracking end-to-end
- [ ] Set up weekly reporting dashboard

Static analysis

No suspicious patterns detected.