Back to skill

Security audit

Analytics Tracking

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent analytics-tracking guidance skill, but users should apply privacy and consent review before copying its tracking examples into production.

Install only if you want analytics implementation help. Before using its examples, confirm your consent flow, avoid sending PII or raw payment details, prefer pseudonymous identifiers, and review third-party destinations such as GA4, Google Ads, Facebook Pixel, Segment, Mixpanel, or Amplitude with your privacy/compliance requirements.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description includes very broad trigger phrases such as 'how do I measure this,' 'how to know if something is working,' and generic references to marketing results. This can cause the agent to invoke the analytics skill for loosely related requests outside its intended scope, increasing the chance of inappropriate context capture, irrelevant guidance, or interference with more suitable skills.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The reference explicitly recommends tracking persistent identifiers such as user_id and account_id alongside payment and purchase-related events, but it provides no privacy, consent, minimization, retention, or sensitive-data handling guidance. In an analytics-tracking skill, this omission is more dangerous because users are likely to copy these schemas directly into production, increasing the risk of over-collection, regulatory noncompliance, and accidental transmission of personal or financial data to third-party analytics platforms.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The reference includes examples that set user_id and user properties such as user_type and plan_name without any accompanying privacy, consent, minimization, or policy guidance. In an analytics implementation skill, this can lead users to deploy identity-linked tracking in ways that violate privacy requirements, platform policies, or internal data-handling standards, especially if identifiers are personally identifying or sent before consent.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
60% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · references/ga4-implementation.md (reported line 229)May include surrounding context.

md
### DebugView

Enable with:
- URL parameter: `?debug_mode=true`
- Chrome extension: GA Debugger
- gtag: `'debug_mode': true` in config

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file describes analytics and ad-tech implementations that capture user identifiers, behavioral events, and purchase details, including userId, ecommerce transaction data, and Facebook Pixel events. Although the file includes a consent section later, it does not clearly warn readers near these examples that the configurations may process personal or sensitive usage data and should only be used with appropriate disclosure and consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.