Analytics Tracking Automation — GA4 + GTM Setup via AI

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's files and runtime instructions are coherent with an end-to-end GA4 + GTM workflow (crawler, schema authoring, Playwright checks, and interactive Google OAuth) but there are small metadata/instruction mismatches and runtime actions you should be aware of before installing.

This skill appears to do what it says: end-to-end GA4 + GTM orchestration using a Playwright crawler and an interactive Google OAuth flow. Before installing or running it: (1) ensure you have Node.js 18+, npm, and Playwright/Chromium available (the registry metadata did not declare these, but SKILL.md requires them); (2) run it in an environment that permits outbound HTTP and a loopback callback on 127.0.0.1 for Google's OAuth; (3) verify the upstream repository/package (bundle.json points to a GitHub repo) before running any npx/npm install or build steps; (4) understand the tool will store a user-generated Google OAuth refresh token locally in the artifact directory — do not commit that file to source control and rotate/revoke if needed; (5) telemetry is opt-in and documented; answer the telemetry prompt explicitly. The skill’s behavior is coherent, but because it includes network installs and runs a browser and Google OAuth, follow standard caution (review repo, run in a controlled environment) before use.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.