Fail-closed Meta Pixel + Conversions API skill for Claude Code. 8 platforms, 19 rules, 56 tests. Agent Skills open standard compatible.
SaferSkills independently audited meta-pixel-capi (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill to produce implementation guidance only when source integrity, platform coverage, and security conditions are satisfied.
manifests/source-registry.json.references/core/unsupported-fallback.md.manifests/source-registry.json and manifests/rule-registry.json.manifests/platform-matrix.json.Always return sections in this exact order:
No extra top-level sections are allowed.
next.jsreactshopifywordpressgohighlevelclickfunnelswebflowstatic-htmlunsupported and use fallback contract.manifests/platform-matrix.json.Require these fields before implementation:
meta_pixel_iddomainevent_map (business funnel steps mapped to Meta standard events)Require these fields for server-side CAPI paths:
capi_access_token (store in env only; never echo)test_event_code for validation phaseDo not ask users to paste secrets into chat history. Ask for confirmation that env vars are set.
references/core/capi-baseline.md.references/platforms/<platform>.md.required_checks in platform matrix.event_id for Pixel + CAPI deduplication.references/core/unsupported-fallback.md.Minimum verification steps for all implementations:
If verification evidence is incomplete, mark status UNVERIFIED.
When any critical condition fails, return only:
status: BLOCKEDreason_codes: list of failing rule IDs or source IDsmissing_or_stale_sourcesmissing_inputsnext_actionsCritical blockers include:
meta_core sources (>14 days)****** except last 4 chars if needed for human debugging).Access-Control-Allow-Origin: *.manifests/source-registry.json.references/core/capi-baseline.mdreferences/core/unsupported-fallback.mdreferences/core/ios-aem-context.mdreferences/security/secret-handling.mdreferences/security/safe-networking.mdreferences/troubleshooting/common-failures.mdPlatform references:
references/platforms/nextjs.mdreferences/platforms/react.mdreferences/platforms/shopify.mdreferences/platforms/wordpress.mdreferences/platforms/gohighlevel.mdreferences/platforms/clickfunnels.mdreferences/platforms/webflow.mdreferences/platforms/static-html.md~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.