Analytics Tracking Automation — GA4 + GTM Setup via AI
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's files and runtime instructions are coherent with an end-to-end GA4 + GTM workflow (crawler, schema authoring, Playwright checks, and interactive Google OAuth) but there are small metadata/instruction mismatches and runtime actions you should be aware of before installing.
This skill appears to do what it says: end-to-end GA4 + GTM orchestration using a Playwright crawler and an interactive Google OAuth flow. Before installing or running it: (1) ensure you have Node.js 18+, npm, and Playwright/Chromium available (the registry metadata did not declare these, but SKILL.md requires them); (2) run it in an environment that permits outbound HTTP and a loopback callback on 127.0.0.1 for Google's OAuth; (3) verify the upstream repository/package (bundle.json points to a GitHub repo) before running any npx/npm install or build steps; (4) understand the tool will store a user-generated Google OAuth refresh token locally in the artifact directory — do not commit that file to source control and rotate/revoke if needed; (5) telemetry is opt-in and documented; answer the telemetry prompt explicitly. The skill’s behavior is coherent, but because it includes network installs and runs a browser and Google OAuth, follow standard caution (review repo, run in a controlled environment) before use.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
