Back to skill

Security audit

analytics-tracking

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only analytics guidance skill, with a privacy caveat around GA4 User ID tracking but no hidden execution or system access.

Before using the User ID guidance, confirm that GA4 receives only an internal pseudonymous authenticated-user identifier, not emails or direct personal identifiers, and verify consent, retention, access controls, and regional privacy requirements. The rest of the skill is ordinary analytics implementation guidance.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill recommends setting a GA4 user_id for cross-device, cross-session identification but does not warn that persistent identifiers can create privacy, consent, and compliance risks. In an analytics implementation skill, omission of guardrails may lead operators to deploy identity-linked tracking without checking GA4 policy restrictions, local privacy laws, or whether the identifier could expose personal data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.