Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Analytics Stack Stinger

ASecurity

Foundational, industry-specific, and lawful-only de-anonymization analytics audit, built on the vendor census. Flags jurisdiction questions rather than a compliance verdict. Wave W5.

85 stars
0 votes
0 copies
0 views
Added 9/27/2026
ai-agentsgogitsecuritydocumentation

Works with

claude codecursor

Security Analysis

A100/100

Pro scans all 12 files and shows the line behind each finding

Scanned 9/27/2026

$npx -y skills add legioncodeinc/vibe-coding-tools --skill analytics-stack-stinger --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Analytics Stack Stinger?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Analytics Stack Stinger
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/legioncodeinc-analytics-stack-stinger/badge)](https://www.skillsdirectory.com/skills/legioncodeinc-analytics-stack-stinger)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: "analytics-stack-stinger"
description: "Foundational, industry-specific, and lawful-only de-anonymization analytics audit, built on the vendor census. Flags jurisdiction questions rather than a compliance verdict. Wave W5."
license: AGPL-3.0-or-later
compatibility: "Claude Code, Cursor, ChatGPT Codex, Claude Cowork."
metadata:
  hive-tier: stinger
  hive-drone: analytics-stack-wasp-drone
  research-window: "2026-08-18 (single sweep)"
  primary-surface: external-website-audit
---

# Analytics Stack Stinger

> **Forge status:** stages 1-6 of the seven-stage forge pipeline complete (Topic, Research, Distillation, References, Guides, final Skill/Drone authorship). Stage 7 (Register, pair registration in `pest-controller-suit` and deploy) has not run yet. Everything below this line is grounded in this pair's PRD, the build plan, and the four raw sources archived in `references/research/raw/`; every claim traces to one of those or is explicitly labelled as general knowledge or inference.

You are equipping **analytics-stack-wasp-drone**, part of the Website Auditor by Legion Code Inc. plugin. Full scope and acceptance criteria: [prd-015-analytics-stack](../../library/requirements/backlog/prd-015-analytics-stack/prd-015-analytics-stack-index.md).

## Purpose

Score a site's analytics and visitor-identification stack across three leaves of the "Analytics and insight" scoring category (12% of the final grade): foundational analytics coverage (5%), industry-specific analytics (4%), and de-anonymization/visitor-identification tooling where lawful (3%). This Stinger builds on `vendor-inventory-wasp-drone`'s third-party census rather than re-detecting vendors from scratch, and it flags legal-gray-area de-anonymization findings distinctly instead of rendering a compliance verdict.

## When to use this skill

- Wave W5 of every audit run, after `01-recon/vendor-inventory.md` and `02-positioning/` both exist.
- Any standalone request specifically about analytics coverage, tag-management-layer composition, or visitor-identification/de-anonymization tooling on an externally-audited site.
- Classifying whether a vendor already surfaced by `vendor-inventory-wasp-drone` belongs in this Stinger's scope versus `web-security-posture-wasp-drone`'s or stays purely with `vendor-inventory-wasp-drone` (content-injection-only vendors).

## When not to use this skill

- Before `01-recon/vendor-inventory.md` or `02-positioning/` exist. This Stinger reads both as inputs and does not re-run vendor detection itself.
- To render a legal/compliance verdict on de-anonymization tooling. That is explicitly out of scope, see `guides/04-deanonymization-and-jurisdiction.md`.
- To score a write-capable content-injection vendor (e.g. a Search Atlas OTTO Pixel-class tool). That class is owned by `vendor-inventory-wasp-drone`, this Stinger only cross-references it.
- For an internal codebase's own analytics instrumentation review. This Stinger assesses a live, externally-audited site with no source access; that is a different posture from a repo-improvement task.

## Procedure

1. Load `01-recon/vendor-inventory.md` and `02-positioning/`.
2. Classify every analytics-relevant vendor into foundational, industry-specific, de-anonymization, or out-of-scope, using `references/templates/vendor-classification-table.md`'s tiered signatures and `references/scripts/analytics-vendor-classify.py` as a spot-check.
3. Cross-check the tag-management layer (`guides/05-tag-manager-and-injection-cross-check.md`) before finalizing scores, GTM is commonly the delivery mechanism for what this Stinger scores.
4. Score each of the three leaves on the plugin-wide zero-to-six scale, every score with a numeric value, an evidence pointer, and a one-line justification.
5. Flag (never adjudicate) any de-anonymization finding's jurisdiction question, per `guides/04-deanonymization-and-jurisdiction.md`.
6. Log rejected/reframed candidates to the run's verification log.
7. Write `08-analytics/analytics-findings.md` from `references/templates/analytics-findings-template.md`, per `guides/06-report-format.md`.

Full step-by-step detail lives in `guides/01-audit-procedure.md`, read it first on every invocation.

## References map

Load on demand; do not read everything up front.

| Path | Load when |
|---|---|
| `guides/01-audit-procedure.md` | Every invocation, read first, full end-to-end sequencing |
| `guides/02-foundational-analytics-coverage.md` | Scoring the 5% foundational-analytics leaf |
| `guides/03-industry-specific-analytics.md` | Scoring the 4% industry-specific leaf, this Stinger's most inference-heavy leaf |
| `guides/04-deanonymization-and-jurisdiction.md` | Any de-anonymization/visitor-identification finding, the flagging discipline, and the company-level vs contact-level, deterministic vs probabilistic distinctions |
| `guides/05-tag-manager-and-injection-cross-check.md` | Google Tag Manager present, or a write-capable content-injection vendor overlaps an analytics classification |
| `guides/06-report-format.md` | Writing the final report and evidence index entries |
| `references/templates/analytics-findings-template.md` | The copy-ready output written to `08-analytics/analytics-findings.md` |
| `references/templates/vendor-classification-table.md` | Classifying any vendor into Tier A (grounded)/Tier B (general knowledge)/Tier C (unconfirmed candidate) |
| `references/scripts/analytics-vendor-classify.py` | Deterministic spot-check classifier over `vendor-inventory.md` or `site-data/` |
| `references/scripts/README.md` | Script inventory and the boundary with `shared/scripts/vendor-census.py` |
| `references/research/distilled-analytics-stack.md` | Verifying any claim fast, or resolving where a fact came from, including this archive's stated gaps |
| `references/research/raw/` | Tracing a claim to its primary source |

## Quality bar

A pass through this Stinger is done when: `guides/01-audit-procedure.md` ran in order, every factual claim used traces to `references/research/raw/` or is explicitly labelled Tier B/general knowledge or `[subjective]`, every score has all three mandatory fields (value, evidence pointer, justification), any de-anonymization finding is flagged rather than adjudicated, rejected/reframed candidates are logged, and `08-analytics/analytics-findings.md` was written per `guides/06-report-format.md`.

## Related drones and stingers

- [analytics-stack-wasp-drone](../../agents/analytics-stack-wasp-drone.md) - this Stinger's paired Drone.
- [vendor-inventory-stinger](../vendor-inventory-stinger) - upstream census this Stinger reads (`01-recon/vendor-inventory.md`); do not duplicate its detection work.
- [icp-positioning-stinger](../icp-positioning-stinger) - upstream niche/ICP determination (`02-positioning/`) this Stinger's industry-specific leaf depends on.
- [web-security-posture-stinger](../web-security-posture-stinger) - owns the broader security/consent posture read; consult when a de-anonymization or tag-manager finding raises a security-adjacent question this Stinger doesn't adjudicate.
- [audit-scoring-stinger](../audit-scoring-stinger) - consumes this Stinger's three leaf scores into the "Analytics and insight" category rollup (12% of the final grade).

## Critical Directive

- You must read all files and context contained within your skill.
- In the event your core knowledge does not provide sufficient guidance you must make every attempt to search the internet, related knowledge base documentation files, and other available resources to supplement your knowledge prior to proceeding with your task.
- Additional related skills can be found here:
  - [analytics-stack-wasp-drone](../../agents/analytics-stack-wasp-drone.md) - this Stinger's paired Drone.
  - [vendor-inventory-stinger](../vendor-inventory-stinger) - upstream third-party census; read its output before running this Stinger's classification pass.
  - [web-security-posture-stinger](../web-security-posture-stinger) - consult for the broader security/consent posture a de-anonymization finding may touch.

## Ship Gate decision

Does not apply to a per-run audit. This Stinger's output is a set of findings written into the customer's audit workspace (`08-analytics/analytics-findings.md`), not a code change to this plugin's own repository, so the security-stinger, quality-stinger, github-repo-health-stinger Ship Gate defined for repo-improvement Drones is not triggered by running an audit. The Ship Gate does apply, per the build plan's Question 22, before any change to this plugin's own source (this file, the paired Drone, shared scripts) is committed and pushed, that is a plugin-development-time gate, not an audit-run-time gate. Do not conflate the two.

Attribution

legioncodeinclegioncodeinc
View sourceSee grades on GitHubMore from legioncodeinc →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →