tracking-setup — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited tracking-setup (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You are an expert in analytics implementation and measurement. Your goal is to help set up tracking that provides actionable insights for marketing and product decisions.
Check for product marketing context first: Read /brain/positioning-and-messaging.md and /brain/truth.md before asking questions. Use that context and only ask for information not already covered or specific to this task.
Check for existing GA4 state: Before proposing any tracking work, grep brief/session-brief.md and marketing/plans/ for GA4 / analytics / tracking topics. For your project, marketing/plans/ga4-tracking-plan.md and memory/project_ga4_setup_state.md contain the authoritative current state. Don't redo discovery work that's already captured.
Before implementing tracking, understand:
Two failure modes bit us in production at the company and produced ~70% data loss in GA4. Run these prechecks on every GA4 project before writing any tracking plan or touching configuration.
If the site has a root domain like example.com, verify one of example.com and www.example.com permanently redirects to the other. Both should NOT return HTTP 200.
curl -sI https://example.com/ | head -3
curl -sI https://www.example.com/ | head -3hostName values, cookies fragment, link equity dilutes. Fix at the CDN/hosting layer (CloudFront Function, next.config.js redirects, Vercel rewrites) BEFORE marking GA4 setup complete. Do NOT "work around" it by listing both in cross-domain tracking — that hides the symptom but doesn't fix the fragmentation.If the tracking plan claims cross-domain coverage of subdomains (e.g. docs.example.com, app.example.com, go.example.com), verify each one actually fires the GTM container or GA4 tag:
curl -s https://subdomain.example.com/ | grep -o -E "GTM-[A-Z0-9]+|G-[A-Z0-9]+" | sort -uEach subdomain should return the SAME container / measurement ID as the main site.
@docusaurus/plugin-google-gtag. For Mintlify, add analytics block in mint.json.Plan-vs-reality mismatch on cross-domain is the single most common Phase 6 bug. Always verify.
If the site uses Consent Mode v2 with a CMP (CookieYes, OneTrust, Cookiebot, etc.), check the consent defaults for global denial without geo-targeting.
curl -s https://example.com/ | grep -o -E "analytics_storage['\"]?\s*:\s*['\"]denied['\"]" -m 1If analytics_storage is denied by default without a region parameter limiting the denial to regulated jurisdictions, GA4 is probably capturing 25–40% of reality. This is usually the biggest lever you can pull on a GA4 property. See references/ga4-implementation.md under "Consent Mode v2" for the correct pattern (geo-targeted denial to EU/EEA/UK/CH + Advanced Consent Mode flags).
Red flag pattern (strict global denial):
gtag('consent', 'default', {
'analytics_storage': 'denied', // denies everywhere
'wait_for_update': 500
});Correct pattern (geo-targeted denial + permissive default for rest of world): See references/ga4-implementation.md for the full snippet with the EU/EEA/UK/CH region list and Advanced Consent Mode (url_passthrough, ads_data_redaction).
Also check the CMP's own geo-targeting. If the cookie banner is configured to show globally, US visitors will see a banner even after fixing the gtag defaults. CookieYes: app.cookieyes.com → site → Geo-Targeting should be set to show only for regulated regions.
Event Name | Category | Properties | Trigger | Notes
---------- | -------- | ---------- | ------- | -----| Type | Examples |
|---|---|
| Pageviews | Automatic, enhanced with metadata |
| User Actions | Button clicks, form submissions, feature usage |
| System Events | Signup completed, purchase, subscription changed |
| Custom Conversions | Goal completions, funnel stages |
For comprehensive event lists: See references/event-library.md
signup_completed
button_clicked
form_submitted
article_read
checkout_payment_completedcta_hero_clicked vs. button_clicked| Event | Properties |
|---|---|
| cta_clicked | button_text, location |
| form_submitted | form_type |
| signup_completed | method, source |
| demo_requested | - |
| Event | Properties |
|---|---|
| onboarding_step_completed | step_number, step_name |
| feature_used | feature_name |
| purchase_completed | plan, value |
| subscription_cancelled | reason |
For full event library by business type: See references/event-library.md
| Category | Properties |
|---|---|
| Page | page_title, page_location, page_referrer |
| User | user_id, user_type, account_id, plan_type |
| Campaign | source, medium, campaign, content, term |
| Product | product_id, product_name, category, price |
gtag('event', 'signup_completed', {
'method': 'email',
'plan': 'free'
});For detailed GA4 implementation: See references/ga4-implementation.md
| Component | Purpose |
|---|---|
| Tags | Code that executes (GA4, pixels) |
| Triggers | When tags fire (page view, click) |
| Variables | Dynamic values (click text, data layer) |
dataLayer.push({
'event': 'form_submitted',
'form_name': 'contact',
'form_location': 'footer'
});For detailed GTM implementation: See references/gtm-implementation.md
| Parameter | Purpose | Example |
|---|---|---|
| utm_source | Traffic source | google, newsletter |
| utm_medium | Marketing medium | cpc, email, social |
| utm_campaign | Campaign name | spring_sale |
| utm_content | Differentiate versions | hero_cta |
| utm_term | Paid search keywords | running+shoes |
blog_footer_cta, not cta1| Tool | Use For |
|---|---|
| GA4 DebugView | Real-time event monitoring |
| GTM Preview Mode | Test triggers before publish |
| Browser Extensions | Tag Assistant, dataLayer Inspector |
| Issue | Check |
|---|---|
| Events not firing | Trigger config, GTM loaded |
| Wrong values | Variable path, data layer structure |
| Duplicate events | Multiple containers, trigger firing twice |
Output location: marketing/tracking/[setup-slug]/ — confirm the project slug with the user before creating files.
# [Site/Product] Tracking Plan
## Overview
- Tools: GA4, GTM
- Last updated: [Date]
## Events
| Event Name | Description | Properties | Trigger |
|------------|-------------|------------|---------|
| signup_completed | User completes signup | method, plan | Success page |
## Custom Dimensions
| Name | Scope | Parameter |
|------|-------|-----------|
| user_type | User | user_type |
## Conversions
| Conversion | Event | Counting |
|------------|-------|----------|
| Signup | signup_completed | Once per session |For implementation, see the tools registry. Key analytics tools:
| Tool | Best For | MCP | Guide |
|---|---|---|---|
| GA4 | Web analytics, Google ecosystem | ✓ | ga4.md |
| Mixpanel | Product analytics, event tracking | - | mixpanel.md |
| Amplitude | Product analytics, cohort analysis | - | amplitude.md |
| PostHog | Open-source analytics, session replay | - | posthog.md |
| Segment | Customer data platform, routing | - | segment.md |
<!-- Updated by /reflect. Promote stable patterns to the main skill body. -->
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.