Skip to content
← Registry
Trust Report

ga4

Read Google Analytics 4 reporting data through the GA4 Data API. Use for explicit GA4 property metadata, compatible metric/dimension reports, traffic analysis, key events, quotas, and bounded exports.

86
CONDITIONAL
Format: openclawScanner: v0.8.1Duration: 8msScanned: 25d ago · Sep 10, 5:36 PMSource →
Embed this badge
AgentVerus CONDITIONAL 86AgentVerus CONDITIONAL 86AgentVerus CONDITIONAL 86
[![AgentVerus](https://agentverus.ai/api/v1/skill/c05d97f1-5697-4d6e-8dc1-5dc499030d79/badge)](https://agentverus.ai/skill/c05d97f1-5697-4d6e-8dc1-5dc499030d79)
Community Discussion

Community Comments

Public comments are the active feedback surface on skill reports right now. Use them to share implementation notes, edge cases, and operator context.

0 comments

Sign in to comment on this skill

No comments yet. Be the first to share your thoughts.

Continue the workflow

Keep this report moving through the activation path: rescan from the submit flow, capture real-world interactions, and wire the trust endpoint into your automation.

https://agentverus.ai/api/v1/skill/c05d97f1-5697-4d6e-8dc1-5dc499030d79/trust
Personalized next commands

Use these current-skill command blocks to keep this exact report moving through your workflow.

Record an interaction
curl -X POST https://agentverus.ai/api/v1/interactions \
  -H "Authorization: Bearer at_your_api_key" \
  -H "Content-Type: application/json" \
  -d '{"agentPlatform":"openclaw","skillId":"c05d97f1-5697-4d6e-8dc1-5dc499030d79","interactedAt":"2026-03-15T12:00:00Z","outcome":"success"}'
Fetch trust JSON
curl https://agentverus.ai/api/v1/skill/c05d97f1-5697-4d6e-8dc1-5dc499030d79/trust

Category Scores

86
Permissions
100
Injection
84
Dependencies
65
Behavioral
65
Content
100
Code Safety

Findings (8)

mediumCapability contract mismatch: inferred filesystem discovery is not declared-8

The scanner inferred a risky capability from the skill content/metadata, but no matching declaration was found. Add a declaration with a clear justification, or remove the behavior.

Content pattern: {baseDir}

→ Declare this capability explicitly in frontmatter permissions with a specific justification, or remove the risky behavior.

permissionsASST-03
mediumCapability contract mismatch: inferred network access is not declared-6

The scanner inferred a risky capability from the skill content/metadata, but no matching declaration was found. Add a declaration with a clear justification, or remove the behavior.

Content pattern: https://developers.google.com/analytics/devguides/reporting/data/v1/basics

→ Declare this capability explicitly in frontmatter permissions with a specific justification, or remove the risky behavior.

permissionsASST-04
mediumThird-party AI provider dependency-8

The skill relies on third-party AI providers or APIs, expanding the remote dependency surface for prompts, inputs, or generated artifacts.

Google Analytics 4 reporting data through the GA4 Data API

→ Review which external services or providers the skill depends on, what data crosses that boundary, and whether the dependency is necessary for the intended workflow.

dependenciesASST-04
mediumHigh-risk workflow lacks explicit safety boundaries-15

The skill performs or enables higher-risk operations but does not define explicit safety boundaries describing what it must not do.

No safety boundary patterns found alongside high-risk capability language

→ Add a 'Safety Boundaries' section listing what the skill must NOT do (e.g., no file deletion, no network access beyond needed APIs).

contentASST-09
mediumMany external URLs referenced (6)-8

The skill references 6 external URLs and also discusses auth/API/payment workflows, which increases the chance that sensitive operations depend on many remote endpoints.

URLs: https://developers.google.com/analytics/devguides/reporting/data/v1/basics, https://developers.google.com/analytics/devguides/reporting/data/v1/rest/v1beta/properties/runReport, https://developers.google.com/analytics/devguides/reporting/data/v1/rest/v1beta/properties/getMetadata, https://developers.google.com/analytics/devguides/reporting/data/v1/rest/v1beta/properties/checkCompatibility, https://developers.google.com/analytics/devguides/reporting/data/v1/api-schema...

→ Minimize external dependencies to reduce supply chain risk.

dependenciesASST-04
mediumUnbounded loops or retries detected-10

Found unbounded loops or retries pattern: "retry indefinitely"

Malformed metadata, compatibility coverage, headers, rows, row counts, or quota values fail the whole bounded request. Never claim a partial report is complete, broaden the OAuth scope, or retry indef

→ Set maximum retry counts and loop bounds to prevent resource exhaustion.

behavioralASST-09
mediumFederated auth flow detected-10

Found federated auth flow pattern: "OAuth" Related auth/profile context: - overlapping signals from the same local context — Skill path discovery detected

Install the dependencies declared in `{baseDir}/requirements.txt` in an isolated Python environment. In Google Cloud, enable the Google Analytics Data API and create a **Desktop app** OAuth client usi

→ Treat OAuth, 2FA, and token-refresh guidance as authentication-sensitive workflows. Explain scope, storage, and refresh behavior clearly so agents do not handle more credential material than necessary.

behavioralASST-05
mediumExternal AI provider delegation detected-10

Found external ai provider delegation pattern: "Google Analytics 4 reporting data through the GA4 Data API"

description: Read Google Analytics 4 reporting data through the GA4 Data API. Use for explicit GA4 property metadata, compatible metric/dimension reports, traffic analysis, key events, quotas, and bou

→ Treat external AI-provider calls as data egress. Make it explicit what prompts, files, or images are sent to third-party providers and require approval before forwarding sensitive content.

behavioralASST-02