Help us improve
Share bugs, ideas, or general feedback.
From vanguard-frontier-agentic
Reviews advertising pixels and event-tracking for personal-data leakage to third-party ad networks. Useful when checking tag-manager containers, pixel snippets, or sensitive pages for data leaks.
npx claudepluginhub raishin/vanguard-frontier-agentic --plugin vanguard-frontier-agenticHow this skill is triggered — by the user, by Claude, or both
Slash command
/vanguard-frontier-agentic:marketing-pixel-data-leakage-reviewThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
This skill reviews advertising pixels and conversion event tracking for unintended exfiltration of personal data to third-party ad networks. Marketing pixels are an attacker-irrelevant but regulator-relevant data path: a pixel that captures an email in a URL parameter, auto-collects form fields, or sits on a health or financial page silently transmits identifiable data to Meta, TikTok, Google, ...
Audits server-side tracking pipelines including sGTM, Meta CAPI Gateway, event deduplication, pixel health, and PII hashing. Useful when evaluating conversion data loss from iOS ATT or ad blockers.
Reviews marketing site consent and data-collection posture — CMP banners, tag-manager containers, Google Consent Mode, cookie policies — for GDPR/CCPA/ePrivacy compliance and dark patterns.
Guides DPIA for marketing analytics including profiling, behavioral targeting, cross-device tracking, and adtech. Covers GDPR Art. 22, ePrivacy cookie consent, PECR, legitimate interest balancing.
Share bugs, ideas, or general feedback.
This skill reviews advertising pixels and conversion event tracking for unintended exfiltration of personal data to third-party ad networks. Marketing pixels are an attacker-irrelevant but regulator-relevant data path: a pixel that captures an email in a URL parameter, auto-collects form fields, or sits on a health or financial page silently transmits identifiable data to Meta, TikTok, Google, or LinkedIn with no contract, no consent scope, and no breach visibility. This pattern has produced large HIPAA settlements, FTC Health Breach Notification Rule actions, and wiretap class actions. The review catches PII in event payloads, form-field auto-capture, pixels on sensitive-context pages, unhashed identifier transmission, and missing data-redaction controls before they ship.
dataLayer value as HIGH — this is uncontracted disclosure of personal data to a third party.location.marketing-consent-data-collection-review.Load these only when needed:
Return, at minimum: