Back to skill

Security audit

Website Analytics

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent read-only website analytics helper, with the main consideration being trust in the third-party fleets CLI and service used for GA4 access.

Install this only if you trust fleets and its npm packages with read-only access to your GA4 and related site analytics. Review the OAuth or token permissions during setup, prefer scoped tokens where available, and remember that analytics data may be sent through the fleets service.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.