Skip to content

Security: arcbaslow/google-analytics-agent

Security

SECURITY.md

Security policy

Reporting a vulnerability

Open a private security advisory on the repo: https://github.com/arcbaslow/google-analytics-agent/security/advisories/new

Please do not file public issues for security problems.

What's in scope

  • Credential handling in scripts/ga4_auth.py and any path that touches ~/.claude/ga4-credentials.json or gcloud ADC files
  • PII handling in scripts/ga4_utils.py (the scrub_pii denylist + regex pass)
  • Any code path that sends user data to a third-party endpoint
  • Any command that performs an Admin API write (event rules, audiences, custom defs, key events) without an explicit confirmation prompt
  • Dependency-chain vulnerabilities in the Google client libraries pinned in scripts/requirements.txt

What's out of scope

  • Misuse of the toolkit against a property you do not own
  • Bugs in the upstream Google APIs themselves — report those to Google
  • Issues that require an attacker with shell access to the user's machine (they already own ~/.claude/)

Where credentials live on disk

  • gcloud ADC (default path): ~/.config/gcloud/application_default_credentials.json
  • Legacy OAuth (fallback path): ~/.claude/ga4-credentials.json (file mode 0600 on POSIX)
  • Service account / external account: GOOGLE_APPLICATION_CREDENTIALS env var

The toolkit never logs credentials to stdout, never sends them to a third party, and never bakes them into report files. Cached API responses under ~/.claude/ga4-cache/ are scrubbed of PII (emails, phone numbers, ID-like keys) before being written.

Disclosure timeline

I aim to acknowledge security reports within 7 days and ship a fix or mitigation within 30 days. For high-severity issues affecting active users, both windows shrink.

PII scrubbing also applies to Admin responses, cached data, context, MCP and rendered reports. Sensitive camelCase/custom-dimension keys and encoded email values are redacted; numeric metrics and GA resource names are retained. Scrubbing is a defensive filter, not a guarantee that arbitrary free text is anonymous. Saved-segment reports use one normal cached, scrubbed Data API call.

The context fetcher validates every redirect destination before following it. Private, loopback, link-local and non-HTTP(S) redirects are refused. DNS rebinding between address validation and connection remains an open limitation.

Website-context fetches validate and pin the numeric destination at socket creation, including every redirect. HTTPS keeps the original hostname for SNI and certificate verification. Proxy environment settings are intentionally ignored for context fetches, and URLs containing credentials are rejected. This may prevent fetching sites reachable only through a proxy; do not bypass the public-address guard. DNS resolution still uses the operating system resolver.

There aren't any published security advisories