analytics-sdk-setup

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill is designed with a strong security and privacy focus. It implements a 'Mode Selection' process (Direct, Plan, or Questions) that forces the agent to analyze the environment and resolve potential blockers before performing any code modifications.
  • [SAFE]: The skill includes comprehensive privacy guardrails, explicitly instructing the agent not to enable Advanced Matching, PII reporting, or Limited Data Use (LDU) without verified requirements and consent sources. This prevents accidental or malicious data exposure.
  • [EXTERNAL_DOWNLOADS]: The skill provides official bootstrap snippets for TikTok Analytics that load resources from the well-known domain analytics.tiktok.com. These are standard industry integration patterns for web tracking and do not pose a security risk.
  • [SAFE]: The skill identifies an indirect prompt injection attack surface by processing untrusted repository code during its 'Repo inspection workflow'. It mitigates this risk through structured thinking steps and explicit boundary markers defined in its 'Output contract', though explicit sanitization of ingested content is not implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 10:27 AM