Agent skill

Analytics

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

MITAuto-check passedMarketing & SEO

Install Analytics

skills CLI
$ npx skills add ericrisco/rsc-harness --skill analytics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness analytics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analytics .claude/skills/analytics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analytics
GitHub stars
156
Token cost
~2.8k tokens
SKILL.md length
1,258 words
Files
7 (incl. scripts, references)
Skills in repo
229
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

  • Works in 5 steps: Event taxonomy first, code second → Wire the SDK → Consent before collection → …
  • Instrumenting product
  • SKILL.md covers When NOT to use, Decision: GA4 vs PostHog vs both, Step 1 — Event taxonomy first,… and Step 2 — Wire the SDK, plus 5 more sections
  • Runs Shell scripts from its folder; reaches googletagmanager.com and eu.posthog.com

What it does

Analytics is an agent skill from ericrisco/rsc-harness. Use when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing. NOT charting that data (that is dashboard), NOT choosing which metrics matter (that is kpi-framework), NOT experiment math (that is ab-testing), NOT cookie-policy text (that is gdpr-privacy).

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/event-taxonomy.md`).

It sits in Marketing & SEO, covering Privacy and GDPR, OKRs and executive reporting and A/B testing. It works with PostHog, Google Analytics and SQL. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Instrumenting product
  • Web analytics — GA4/PostHog SDK wiring
  • Double-counted events

Example prompts

  • “/analytics”

Requirements

  • A Bash shell

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Event taxonomy first, code second
  2. Wire the SDK
  3. Consent before collection
  4. PII discipline
  5. Funnels & validation

What it can do on your machine

Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • googletagmanager.com
    • eu.posthog.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analytics loads about 2.8k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,258 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,258 words, ~2,847 tokens.

Download SKILL.mdSave it as .claude/skills/analytics/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
analytics
description
Use when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing. NOT charting that data (that is dashboard), NOT choosing which metrics matter (that is kpi-framework), NOT experiment math (that is ab-testing), NOT cookie-policy text (that is gdpr-privacy).
tags
analytics, ga4, posthog, event-tracking, telemetry, consent-mode, funnels, privacy
recommends
kpi-framework, ab-testing, gdpr-privacy, nextjs, dashboard, clickhouse-analytics
origin
risco

Analytics — the instrumentation layer

This skill owns the capture side of analytics: deciding what to track, how to name it, where the SDK lives in the codebase, and how not to leak PII or break consent law. It produces three checkable artifacts — an event taxonomy, tracking code (GA4 and/or PostHog), and a consent wiring. Everything downstream of capture (charts, KPI choice, experiment stats, raw-event SQL, legal text) belongs to a sibling; see the routing table below.

The order of work is fixed: taxonomy → SDK wiring → consent gate → PII scrub → funnel + validation.

When NOT to use

The askRoute to
Chart the captured data on a boarddashboard
Decide which metrics matter (North Star, AARRR)kpi-framework
Scheduled stakeholder reports / exportsreporting
Variant assignment, significance, experiment designab-testing (PostHog experiments live there; PostHog event capture lives here)
Query a warehouse of raw events with SQLclickhouse-analytics / duckdb / sql
App error/trace/uptime telemetry (Sentry, OpenTelemetry)observability
Cookie-banner legal text, DPA, ROPA, subject rightsgdpr-privacy / data-policy
Predict future values from a seriesforecasting

The load-bearing line: analytics = events flow in; dashboard/reporting = events flow out.

Decision: GA4 vs PostHog vs both

You needPick
Web/ads attribution, Google Ads conversions, marketing audiencesGA4
Product behavior, funnels, feature flags, session replay, self-serve insightsPostHog
Both marketing attribution and deep product analytics (very common)Both — GA4 for ads, PostHog for product

Running both is normal and fine. Keep one taxonomy shared across both so a purchase means the same thing everywhere. Do not let the two tools drift into two naming schemes.

Step 1 — Event taxonomy first, code second

An event name is a contract: design the taxonomy before you write a single SDK call, and never rename a live event in production. Every funnel, audience, dashboard, and saved insight downstream is keyed by the exact event name and property keys. Rename signup_completed to sign_up after launch and you silently fork the metric into two — the old funnel flatlines, the new one starts from zero, and nobody notices for a week. You can add events forever; you can never safely rename one.

Name events object_action in snake_case: signup_completed, checkout_started, invoice_paid. The object is the noun, the action is a past-tense verb. Detail goes in properties, never in the name — cta_clicked with { location: "navbar" }, not three events navbar_cta, hero_cta, footer_cta.

GA4 hard constraints (the SDK silently truncates or drops violators): event names ≤ 40 chars, alphanumeric + underscore only, must start with a letter; ≤ 25 params per event; ≤ 25 user properties. Prefer GA4 recommended events — sign_up, login, purchase, add_to_cart, search, generate_lead — with their prescribed params, because they unlock prebuilt reports and audiences you cannot get from a custom name.

text
Bad                              Good
"Clicked The Big Button"    →    cta_clicked          { location: "hero" }
trackSignup_v2              →    signup_completed     { method: "google" }
purchaseEvent2              →    purchase             { value: 49, currency: "EUR" }
NavbarCheckoutButton        →    checkout_started     { source: "navbar" }

Identify vs anonymous. Before login the user is anonymous (client_id / distinct_id). On authentication, call identify(stableUserId, { plan, signup_date }) — the stable id is your DB user id, a UUID, never the email. On logout call reset() so the next visitor on a shared machine does not inherit the previous person. The full starter SaaS + e-commerce catalog and property conventions are in references/event-taxonomy.md.

Step 2 — Wire the SDK

GA4 with the global site tag (Next.js Script shown; the consent block in Step 3 must run before this):

html
<script async src="https://www.googletagmanager.com/gtag/js?id=G-XXXXXXXXXX"></script>
<script>
  window.dataLayer = window.dataLayer || [];
  function gtag(){ dataLayer.push(arguments); }
  gtag('js', new Date());
  gtag('config', 'G-XXXXXXXXXX');
</script>

PostHog (posthog-js) — the cost/privacy-correct defaults:

ts
import posthog from 'posthog-js';

posthog.init('phc_xxx', {
  api_host: '/ingest',              // reverse proxy: first-party path beats ad-blockers
  ui_host: 'https://eu.posthog.com',
  person_profiles: 'identified_only', // no profile per anonymous visitor — cheaper, more private
  defaults: '2025-05-24',
  // autocapture: false,            // turn off if you want a deliberate, named-only taxonomy
});

// on login:  posthog.identify(user.id, { plan: user.plan });
// on logout: posthog.reset();

person_profiles: 'identified_only' is the recommended default — it avoids creating a person profile for every anonymous visitor. A reverse proxy (serving the SDK + ingestion under a first-party path like /ingest) is standard practice for both PostHog and GA to dodge ad-blockers and tracking-prevention.

Server-side capture for actions off the browser — payment confirmation, webhooks, cron. With @posthog/next, await getPostHog() works in server components, route handlers, and server actions; it reads identity from the PostHog cookie (and opts the route into dynamic rendering, since it calls cookies()). GA4 server events use the Measurement Protocol with the client_id. Full snippets — gtag install, Consent Mode v2, Measurement Protocol, recommended-event param tables — are in references/ga4-setup.md and references/posthog-setup.md.

Decision: do you serve EEA / UK / CH traffic? If yes, Consent Mode v2 is not optional. Since 21 July 2025 Google enforces it for EEA/UK traffic: tags without connected consent signals lose conversion tracking, remarketing, and demographics. Four params are required and default to denied for EEA/UK/CH:

html
<!-- This block MUST run BEFORE the gtag('config', ...) call in Step 2. Order is load-bearing. -->
<script>
  window.dataLayer = window.dataLayer || [];
  function gtag(){ dataLayer.push(arguments); }
  gtag('consent', 'default', {
    ad_storage: 'denied',
    ad_user_data: 'denied',
    ad_personalization: 'denied',
    analytics_storage: 'denied',
    wait_for_update: 500,
  });
  // when the banner is accepted:
  // gtag('consent', 'update', { analytics_storage: 'granted', ad_storage: 'granted', ... });
</script>

PostHog's equivalent is posthog.optOut() / posthog.optIn() — start opted-out for EEA visitors and opt in on acceptance. The legal text of the banner (what it says, the DPA, retention) is gdpr-privacy's job; this skill only wires the signal the banner emits. Region-scoped defaults live in references/ga4-setup.md.

Show full SKILL.md (525 more words)Show less

Step 4 — PII discipline

Never pass these into a capture( / gtag('event' / track( call. They turn an analytics store into a breach-reportable PII store and violate most processing agreements:

Banned in event propsAllowed instead
email, phone, full namea hashed id, or set on the person profile only — not on every event
raw IP, geolocation coordslet the SDK derive coarse geo server-side
password, token, secret, API keys, session_idnothing — these never belong in analytics
credit_card, ssn, IBANnothing

Scrub at the boundary — a single capture() wrapper that strips known PII keys is far safer than trusting every call site. A GA4 user_id is a stable opaque identifier, not an email; sending an email as the user_id is a PII leak and a violation of Google's policy.

Step 5 — Funnels & validation

Define the funnel from the named events, in order, e.g. signup_started → signup_completed → project_created → invoice_paid. The funnel is only as reliable as the names, which is why Step 1 comes first.

Before you ship, validate — do not trust that it works:

  • GA4: open the DebugView (or watch the network tab for /g/collect hits) and confirm each event fires once with the right params.
  • PostHog: watch the Activity / live events feed; confirm distinct_id is stable across the session.
  • Do not fire events on render. A capture() in a React component body or an unguarded useEffect re-fires on every re-render and double-counts. Fire on the user action, or in a useEffect with a correct dependency array / a fire-once guard.
  • Stitching: GA4 Measurement Protocol events must arrive within 48h of the client-side timestamp to stitch to the right client_id. If you set user_id server-side, set the same user_id browser-side or you create duplicate users.
  • Checking a PostHog feature flag emits a $feature_flag_called event — expected, not a bug; budget for it.

Verify

Run scripts/verify.sh [path] (default: cwd). It is a read-only static lint, never a network call. It flags: PII-looking literals inside capture( / gtag('event' / .track( calls; GA4 event names that break the ≤ 40-char / leading-letter / charset rule; GA present without a gtag('consent','default' gate; and posthog.init( with no host (reverse-proxy reminder). It exits 0 on a clean or empty target.

Anti-patterns

Anti-patternWhy it bitesDo instead
Rename a live event in prodForks the metric; old funnel flatlines, new one starts at zeroAdd a new event; deprecate the old one in a doc, never rename
Treat autocapture as the taxonomyAutocapture is noisy DOM events, not your domain — funnels become unbuildableDesign named domain events; autocapture is a supplement
Email/token in event propsTurns analytics into a breach-reportable PII store; violates the DPAScrub at a capture() wrapper; ids only
No consent gate for EEA/UKSince 21 Jul 2025, Google drops conversions/remarketing/demographicsgtag('consent','default', denied) before config; PostHog optOut
capture() in render / unguarded effectRe-fires every re-render → double-countingFire on the action or a fire-once-guarded effect
Server user_id ≠ browser user_idCreates duplicate users; funnel splitsUse the same stable id on both sides; stitch within 48h
posthog.init with no proxy hostAd-blockers eat ~20-40% of eventsServe SDK + ingest under a first-party path (/ingest)
Email as GA4 user_idPII leak + Google policy violationA stable opaque id (DB id / UUID)

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in skills/analytics of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/event-taxonomy.md
  • references/ga4-setup.md
  • references/posthog-setup.md
  • scripts/verify.sh

Open the folder on GitHubat commit 92fde8f

Compare with similar skills

Analytics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analytics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analytics this skillericrisco/rsc-harness156—~2.8kAutomated safety check: PassMIT
Analytics And Reportingsocial-media-skills/skills116—~1.4kAutomated safety check: PassMIT
SEO Analiticaricneves-ai/flowgrammers-skills115—~2.3kAutomated safety check: PassMIT
Product Marketing Context Globalminhnv0807/ai-business-skills608—~2.1kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
High Token ModeLomnus-ai/TokenBurner173—~9.1kAutomated safety check: PassMIT

Similar skills

  • Analytics And Reporting

    social-media-skills/skills

    Social media analytics and reporting — read native platform data honestly and turn it into next actions.

    116 GitHub stars~1.4k tokensUpdated 5 days ago
    Marketing & SEOAuto-check passed
  • SEO Analitica

    ricneves-ai/flowgrammers-skills

    Skills para otimização de SEO técnico, análise de dados, criação de dashboards e inteligência de negócio para empresas brasileiras.

    115 GitHub stars~2.3k tokensUpdated 11 days ago
    Legal & ComplianceAuto-check passed
  • Product Marketing Context Global

    minhnv0807/ai-business-skills

    A skill your agent uses when starting work on a new product, client, or market — this skill creates the file .agents/product-marketing-context-global.md that 60+ other global skills read before they…

    608 GitHub stars~2.1k tokensUpdated 25 days ago
    Marketing & SEOAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • High Token Mode

    Lomnus-ai/TokenBurner

    Forces heavy internal computation (thinking tokens) before each response.

    173 GitHub stars~9.1k tokensUpdated 5 mo ago
    Testing & QAAuto-check passed
  • Analytics Insights

    indranilbanerjee/digital-marketing-pro

    Marketing measurement module — builds KPI trees per business model, reporting templates (weekly, monthly, QBR, campaign), anomaly root-cause diagnosis, MMM and incrementality guidance, dark-social…

    854 GitHub starsUsed in 1 repo~6.7k tokens
    Marketing & SEOAuto-check passed

More from ericrisco/rsc-harness

All 229 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    156 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    156 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    156 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    156 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    156 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Angular

    ericrisco/rsc-harness

    A skill your agent uses when building, refactoring, or debugging Angular (v20/21+): standalone components, signals, zoneless change detection, @if/@for/@defer control flow, inject() DI…

    156 GitHub stars~3.4k tokensUpdated today
    Auto-check passed

Questions about Analytics

What does Analytics do?

A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing. Analytics is an agent skill from ericrisco/rsc-harness. Use when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

When should I use Analytics?

Analytics fits situations like: instrumenting product; web analytics — GA4/PostHog SDK wiring; double-counted events.

How do I install Analytics in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill analytics -a claude-code`. Or copy the skill folder (skills/analytics in ericrisco/rsc-harness) into .claude/skills/analytics in your project. Claude Code loads it when a task matches its description.

How do I install Analytics in Codex?

Run `npx skills add ericrisco/rsc-harness --skill analytics -a codex`. Or copy the skill folder (skills/analytics in ericrisco/rsc-harness) into .agents/skills/analytics in your project. Codex loads it when a task matches its description.

Can I use Analytics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill analytics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analytics, .gemini/skills/analytics, .github/skills/analytics and .opencode/skills/analytics in your project.

What does Analytics need to run?

Going by SKILL.md and its folder, Analytics needs a shell for the scripts in its folder. Our summary lists: A Bash shell.

Does Analytics access the network?

SKILL.md names 2 domains. In commands or code: googletagmanager.com and eu.posthog.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Analytics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Analytics use?

Analytics is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analytics use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3k tokens, read only when the agent opens those files.

What are the alternatives to Analytics?

Skills that share tags, products or a category with Analytics: Analytics And Reporting (social-media-skills/skills, 116 stars), SEO Analitica (ricneves-ai/flowgrammers-skills, 115 stars), Product Marketing Context Global (minhnv0807/ai-business-skills, 608 stars) and C15t (c15t/c15t, 1.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analytics?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.