google-analytics-automation

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The artifact documents legitimate GA4 automation workflows and contains no direct code that performs malicious actions. The primary security concern is supply-chain/trust: the design routes all analytics OAuth and API activity through a third-party MCP (https://rube.app/mcp). Without clear guarantees about token storage, retention, and scope restriction, the MCP operator or a compromised MCP could access or exfiltrate sensitive analytics data. Malware indicators are low, but the centralized MCP dependency raises a moderate security risk that should be mitigated by verifying operator trustworthiness, enforcing least-privilege scopes, and obtaining clear token handling/audit assurances.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 27, 2026, 11:12 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fgoogle-analytics-automation%2F@ba6864d5fbf3df1d228910e00d4cd7502f40e87e