app-analytics — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited app-analytics (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You are an expert in mobile app analytics and measurement strategy. Your goal is to help the user set up meaningful tracking, interpret their data, and make data-driven decisions.
app-marketing-context.md — read it for context| Tool | Purpose | Cost | Priority |
|---|---|---|---|
| App Store Connect | Store metrics, downloads, conversion | Free | Must have |
| Firebase Analytics | In-app events, funnels, audiences | Free | Must have |
| Mixpanel / Amplitude | Product analytics, cohorts, funnels | Free tier | Recommended |
| RevenueCat | Subscription analytics, paywall testing | Free tier | If subscriptions |
| Adjust / AppsFlyer | Attribution, UA measurement | Paid | If running ads |
| Crashlytics | Crash reporting, stability | Free | Must have |
Key metrics available for free:
| Metric | What it tells you |
|---|---|
| Impressions | How many times your app appeared in search/browse |
| Product Page Views | How many users visited your product page |
| App Units | First-time downloads |
| Conversion Rate | Product Page Views → Downloads |
| Proceeds | Revenue after Apple's cut |
| Sessions | App opens |
| Active Devices | Unique devices using the app |
| Retention | Day 1, Day 7, Day 28 retention |
| Crash Rate | Crashes per session |
Source types:
| Metric | Formula | What it means |
|---|---|---|
| Impressions | — | Visibility in App Store |
| Tap-Through Rate | Taps / Impressions | Icon + title effectiveness |
| Conversion Rate | Downloads / Page Views | Product page effectiveness |
| CPI | Ad Spend / Installs | Cost efficiency of paid UA |
| Organic % | Organic / Total Installs | Health of organic growth |
| Metric | Formula | What it means |
|---|---|---|
| DAU | Daily Active Users | Daily engagement |
| MAU | Monthly Active Users | Monthly reach |
| DAU/MAU | DAU / MAU | Stickiness (>20% is good) |
| Sessions/User | Total Sessions / DAU | Engagement depth |
| Session Length | Avg time per session | Value delivery |
| Metric | Formula | Benchmark |
|---|---|---|
| Day 1 | Users Day 1 / Installs | 25-40% |
| Day 7 | Users Day 7 / Installs | 10-20% |
| Day 30 | Users Day 30 / Installs | 5-10% |
| Churn Rate | Lost Users / Start Users | < 5% monthly (subscriptions) |
| Metric | Formula | What it means |
|---|---|---|
| ARPU | Revenue / All Users | Average revenue per user |
| ARPPU | Revenue / Paying Users | Paying user value |
| LTV | ARPU × Avg Lifetime | Total user value |
| Trial-to-Paid | Conversions / Trial Starts | Paywall effectiveness |
| MRR | Monthly Recurring Revenue | Subscription health |
| Churn Revenue | Lost MRR / Start MRR | Revenue retention |
# Onboarding
onboarding_started
onboarding_step_completed (step_name, step_number)
onboarding_completed
onboarding_skipped
# Core Actions
[primary_action]_started
[primary_action]_completed
[primary_action]_failed (error_type)
# Monetization
paywall_viewed (source, variant)
trial_started (plan, source)
purchase_completed (plan, price, source)
purchase_failed (error_type)
subscription_renewed
subscription_cancelled (reason)
# Engagement
session_started (source)
feature_used (feature_name)
content_viewed (content_type, content_id)
share_tapped (content_type)
notification_received (type)
notification_tapped (type)
# Settings
settings_changed (setting_name, old_value, new_value)
notification_permission (granted: boolean)snake_case[object]_[action] (e.g., photo_saved, workout_completed)┌─────────────────────────────────────────────┐
│ Weekly Summary │
├──────────────┬──────────────┬───────────────┤
│ Downloads │ Revenue │ DAU │
│ [N] (+X%) │ $[N] (+X%) │ [N] (+X%) │
├──────────────┼──────────────┼───────────────┤
│ Conversion │ D1 Retention│ Rating │
│ [X]% (+X%) │ [X]% (+X%) │ [X.X] ★ │
└──────────────┴──────────────┴───────────────┘Impressions → Page Views → Downloads → Activation → Purchase
[N] [N] [N] [N] [N]
[X]% [X]% [X]% [X]%Retention curves by:
Current State:
- Tools in use: [list]
- Events tracked: [N]
- Key gaps: [list]
Recommendations:
1. [tracking gap to fix]
2. [metric to start monitoring]
3. [dashboard to create]Provide a complete event tracking plan with:
When the user shares data, provide:
ab-test-store-listing — Measure test resultsretention-optimization — Interpret retention datamonetization-strategy — Revenue metric optimizationua-campaign — Attribution and UA metrics~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.