Is codeninja23/native-google-analytics safe?
Yes. codeninja23/native-google-analytics is safe to install. Oathe's behavioral security audit gave the native-google-analytics skill by codeninja23 a trust score of 96/100 with 3 findings, none critical or high.
https://clawhub.ai/codeninja23/native-google-analytics
Is codeninja23/native-google-analytics safe to install?
This Google Analytics skill is a legitimate API client for querying GA4 data with read-only access. The skill contains standard Python API client code and follows Google's recommended OAuth authentication patterns with appropriate read-only scope limitations.
What security issues were found in codeninja23/native-google-analytics?
Category Scores
Findings (3)
LOW Contains executable Python scripts -15 ▶
The skill includes two Python scripts (ga4_auth.py and ga4_query.py) that are executable. These are legitimate API client tools for Google Analytics authentication and querying, using standard OAuth flows and HTTPS API calls.
INFO Monitoring detected sensitive file access -5 ▶
System monitoring detected access to sensitive files (.env, SSH keys, AWS credentials) during the monitoring period. However, this occurred during system startup (09:27:29) rather than during skill installation, and appears unrelated to the skill itself.
INFO Requires OAuth credentials for Google APIs -5 ▶
The skill requires Google OAuth credentials (CLIENT_ID, CLIENT_SECRET, REFRESH_TOKEN) to function, but uses the read-only 'analytics.readonly' scope which limits access to viewing analytics data only.
Should I install codeninja23/native-google-analytics?
Oathe's verdict for codeninja23/native-google-analytics is SAFE with a trust score of 96/100. Recommendation: Install.