GitHub Issues
scify/laravel-cookie-guard
Fetches open GitHub issues for the current repository using the gh CLI.
Implementing server-side tracking with privacy controls using Google Tag Manager server containers.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill server-side-tracking -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills server-side-tracking --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/server-side-tracking .claude/skills/server-side-tracking && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "server-side-tracking" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/server-side-tracking into .claude/skills/server-side-tracking/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "server-side-tracking", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/server-side-trackingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill server-side-tracking -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills server-side-tracking --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/server-side-tracking .agents/skills/server-side-tracking && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "server-side-tracking" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/server-side-tracking into .agents/skills/server-side-tracking/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "server-side-tracking", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill server-side-tracking -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills server-side-tracking --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/server-side-tracking .cursor/skills/server-side-tracking && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "server-side-tracking" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/server-side-tracking into .cursor/skills/server-side-tracking/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "server-side-tracking", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/server-side-tracking--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill server-side-tracking -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills server-side-tracking --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/server-side-tracking .gemini/skills/server-side-tracking && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "server-side-tracking" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/server-side-tracking into .gemini/skills/server-side-tracking/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "server-side-tracking", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills server-side-trackingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill server-side-tracking -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/server-side-tracking .github/skills/server-side-tracking && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "server-side-tracking" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/server-side-tracking into .github/skills/server-side-tracking/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "server-side-tracking", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill server-side-tracking -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills server-side-tracking --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/server-side-tracking .opencode/skills/server-side-tracking && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "server-side-tracking" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/server-side-tracking into .opencode/skills/server-side-tracking/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "server-side-tracking", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
server-side-trackingImplementing server-side tracking with privacy controls using Google Tag Manager server containers.
Server Side Tracking is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implementing server-side tracking with privacy controls using Google Tag Manager server containers. Covers first-party data collection, IP anonymization, consent-aware event forwarding, and reducing client-side third-party cookie exposure.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Backend & APIs, covering Backend development and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
data.pinnacle-ecommerce.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Server Side Tracking loads about 2.4k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 887 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 887 words, ~2,379 tokens.
.claude/skills/server-side-tracking/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Server-side tracking moves data collection from the user's browser to a server-controlled environment, providing greater control over what data is shared with third parties. Instead of loading third-party JavaScript directly in the browser (which sets third-party cookies and sends data to external servers without intermediation), a server-side container receives events from the client, processes them, and selectively forwards data to analytics and advertising endpoints. This architecture enables IP anonymization before data leaves the first-party infrastructure, consent-based routing of events, and reduced reliance on third-party cookies — directly supporting ePrivacy Directive Article 5(3) compliance and data minimization under GDPR Article 5(1)(c).
User's Browser
│
├── Client-side GTM container (minimal)
│ └── Sends events to first-party endpoint
│
▼
First-Party Server Endpoint
(https://data.pinnacle-ecommerce.com)
│
├── Server-side GTM container
│ ├── Validates consent state
│ ├── Anonymizes IP address
│ ├── Strips unnecessary identifiers
│ ├── Applies data minimization rules
│ │
│ ├── [If analytics consent granted]
│ │ └── Forward to Google Analytics 4
│ │
│ ├── [If advertising consent granted]
│ │ ├── Forward to Google Ads
│ │ ├── Forward to Meta Conversions API
│ │ └── Forward to other ad platforms
│ │
│ └── [If all consent denied]
│ └── Log aggregate pageview count only (no PII)
│
└── First-party server logs (retention: 90 days)Server Container Hosting Options:
| Option | Provider | Monthly Cost (est.) | Latency | Control |
|---|---|---|---|---|
| Google Cloud Run | Google Cloud | EUR 50-200 | Low | High |
| AWS App Runner | Amazon Web Services | EUR 40-180 | Low | High |
| Custom Docker | Self-hosted | EUR 30-150 | Varies | Maximum |
| Stape.io | Managed service | EUR 20-100 | Low | Medium |
Pinnacle E-Commerce Ltd Configuration:
| Setting | Value |
|---|---|
| Server container URL | https://data.pinnacle-ecommerce.com |
| Custom domain | data.pinnacle-ecommerce.com (CNAME to container) |
| Container region | europe-west1 (Belgium) — co-located with EU users |
| Scaling | Min 1 instance, max 10 instances |
| SSL certificate | Let's Encrypt via managed certificate |
| First-party cookie domain | .pinnacle-ecommerce.com |
Using a subdomain of the main site domain ensures:
data.pinnacle-ecommerce.com are same-site, avoiding third-party cookie restrictionsDNS Configuration:
data.pinnacle-ecommerce.com CNAME server-container-abc123.run.appEvery event arriving at the server container includes the consent state from the client. The server validates this before forwarding:
Event Payload from Client:
{
"client_id": "1234567890.1709000000",
"event_name": "purchase",
"event_params": {
"transaction_id": "TXN-2026-0314-001",
"value": 149.99,
"currency": "EUR",
"items": [{"item_id": "SKU-001", "item_name": "Widget Pro"}]
},
"consent_state": {
"analytics_storage": "granted",
"ad_storage": "denied",
"ad_user_data": "denied",
"ad_personalization": "denied"
},
"user_agent": "Mozilla/5.0...",
"ip_address": "203.0.113.42"
}Server-Side Routing Logic:
| Destination | Required Consent | Data Sent |
|---|---|---|
| GA4 Measurement Protocol | analytics_storage: granted | Event name, params, anonymized client_id |
| Google Ads Conversion API | ad_storage + ad_user_data: granted | Conversion data, gclid, hashed email |
| Meta Conversions API | ad_storage + ad_user_data: granted | Event data, fbp, hashed email/phone |
| Aggregate counter (internal) | None required | +1 to event type counter (no PII) |
The server container anonymizes IP addresses before forwarding to any third party:
Anonymization Rules:
| Method | Description | Use Case |
|---|---|---|
| IPv4 last octet zeroing | 203.0.113.42 → 203.0.113.0 | Standard GA4 anonymization |
| IPv6 last 80 bits zeroing | 2001:db8::1234:5678 → 2001:db8:: | IPv6 anonymization |
| Full IP removal | IP not forwarded at all | Maximum privacy (Meta CAPI) |
| Geolocation-only | Resolve to country/region, discard IP | Geo reporting without IP |
Pinnacle E-Commerce Ltd Policy:
The server container strips data before forwarding:
| Data Element | Retained for GA4 | Retained for Ads | Retained Internally |
|---|---|---|---|
| Full URL | Path only (no query params) | Path only | Full URL (90 days) |
| User agent | Reduced UA (SEC-CH-UA) | Reduced UA | Full UA (24 hours) |
| IP address | Anonymized | Anonymized | Full (24 hours) |
| Referrer | Domain only | Domain only | Full (90 days) |
| Client ID | GA client_id | gclid/wbraid only | Internal session ID |
| Email (hashed) | Not sent | SHA-256 hash | Not stored |
| Setting | Value |
|---|---|
| Measurement ID | G-PINNACLE123 |
| API Secret | Stored in Secret Manager |
| Send to | GA4 Measurement Protocol |
| IP anonymization | Enabled (default in GA4) |
| Client ID source | First-party _ga cookie |
| Session ID source | First-party ga* cookie |
| Setting | Value |
|---|---|
| Pixel ID | 123456789012345 |
| Access Token | Stored in Secret Manager |
| Event deduplication | event_id matches browser Pixel event_id |
| Data sent | Event name, event_time, action_source, hashed email |
| IP forwarding | Disabled |
| User agent forwarding | Reduced UA only |
The server container can set first-party cookies via Set-Cookie headers, giving them longer lifetimes than client-side JavaScript cookies (which Safari ITP caps at 7 days):
| Cookie | Set By | Duration | Purpose |
|---|---|---|---|
| _ga | Server (Set-Cookie header) | 2 years | GA4 client identifier |
| _ga_PINNACLE | Server (Set-Cookie header) | 2 years | GA4 session persistence |
| _fbc | Server (Set-Cookie header) | 90 days | Meta click identifier |
| _pin_sess | Server (Set-Cookie header) | 30 minutes | Internal session tracking |
All cookies above are set only when the corresponding consent category is granted.
| Metric | Target | Alert Threshold |
|---|---|---|
| Request latency (p99) | < 200ms | > 500ms |
| Error rate | < 0.1% | > 1% |
| Event throughput | Baseline +/- 20% | > 30% deviation |
| Consent validation failures | 0 | > 0 |
| Forwarding failures (GA4) | < 0.5% | > 2% |
| Forwarding failures (Meta) | < 1% | > 5% |
Monthly audit of server-side tracking:
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/server-side-tracking of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Server Side Tracking next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Server Side Tracking this skillmukul975/Privacy-Data-Protection-Skills | 295 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| GitHub Issuesscify/laravel-cookie-guard | 148 | — | ~170 | Automated safety check: Pass | Apache-2.0 | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| Fortify Developmentcoollabsio/coolify | 63k | 4 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Node Backend Development Guidelinesdiet103/claude-code-infrastructure-showcase | 10k | 2 repos | ~2k | Automated safety check: Pass | MIT | |
| Laravel Best Practicesanonaddy/anonaddy | 4.9k | 13 repos | ~1.2k | Automated safety check: Pass | MIT |
scify/laravel-cookie-guard
Fetches open GitHub issues for the current repository using the gh CLI.
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
diet103/claude-code-infrastructure-showcase
Sets layered architecture and coding rules for Node.js, Express and TypeScript microservices, covering routes, controllers, services, repositories, Prisma, Sentry and Zod.
anonaddy/anonaddy
Apply this skill whenever writing, reviewing, or refactoring Laravel PHP code.
coollabsio/coolify
Build, refactor, and troubleshoot Laravel Actions using lorisleiva/laravel-actions.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
mukul975/Privacy-Data-Protection-Skills
Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.
Categories
Implementing server-side tracking with privacy controls using Google Tag Manager server containers. Server Side Tracking is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implementing server-side tracking with privacy controls using Google Tag Manager server containers.
Server Side Tracking fits situations like: tasks that involve Backend development; tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill server-side-tracking -a claude-code`. Or copy the skill folder (skills/privacy/server-side-tracking in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/server-side-tracking in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill server-side-tracking -a codex`. Or copy the skill folder (skills/privacy/server-side-tracking in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/server-side-tracking in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill server-side-tracking -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/server-side-tracking, .gemini/skills/server-side-tracking, .github/skills/server-side-tracking and .opencode/skills/server-side-tracking in your project.
Going by SKILL.md and its folder, Server Side Tracking needs Python for the scripts in its folder. Our summary lists: Python 3; Docker.
SKILL.md names 1 domain. In commands or code: data.pinnacle-ecommerce.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Server Side Tracking is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Server Side Tracking: GitHub Issues (scify/laravel-cookie-guard, 148 stars), Configuring Horizon (coollabsio/coolify, 63k stars), Fortify Development (coollabsio/coolify, 63k stars) and Node Backend Development Guidelines (diet103/claude-code-infrastructure-showcase, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.