Skills paid-measurement-loop
πŸ“¦

paid-measurement-loop

v19.0.0 Content revision r2 Medium Risk βš™οΈ External commands🌐 Network accessπŸ“ Filesystem access

Evaluate Paid Campaign Changes with Controls

Paid campaign changes can look successful when attribution, learning phase, or seasonal effects distort results. This skill compares a fixed candidate window with a control and gives a documented decision.

Supports: Claude Codex Code(CC)
πŸ“Š 72 Adequate

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "paid-measurement-loop" from https://skillstore.io/skills/aaron-he-zhu-paid-measurement-loop.md and its manifest at https://skillstore.io/api/skills/aaron-he-zhu-paid-measurement-loop/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "paid-measurement-loop". Review a 14-day budget increase against an unchanged control.

Expected outcome:

  • Decision: Keep-testing
  • ROAS improved versus the control, but the uncertainty evidence is not yet sufficient.
  • Next step: retain the fixed window and read back again in seven days.

Using "paid-measurement-loop". Compare new creative with the control using CPA exports.

Expected outcome:

  • Decision: Rollback
  • Candidate CPA is worse than the control after normalized attribution review.
  • Record the control, window, and source labels in the readback summary.

Security Audit

Medium Risk
v8 β€’ 7/27/2026 Open versioned report

Most static alerts are false positives caused by Markdown code formatting and static repository links. One instructed ledger command interpolates a campaign placeholder into a shell command, and the result filename convention lacks a campaign-name sanitization rule. No prompt injection, credential collection, or unauthorized network behavior was found.

1
Files scanned
86
Lines analyzed
1
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Unsanitized campaign name in result filename
The save convention inserts the campaign name into a result filename without specifying a safe character set. A campaign name containing path separators could write outside the intended results directory if implemented literally.
The filename template explicitly includes a campaign placeholder and gives no sanitization rule. Exploitability depends on the host implementation, but the instruction creates a clear path-handling hazard.
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Ruby/shell backtick execution
5. **Snapshot to the ledger.** Record baseline and candidate signals so the delta is computed, not e
The skill instructs a shell command that interpolates the campaign placeholder without quoting or argument validation. A campaign value containing shell metacharacters could alter command execution.
Audited by: claude View Audit History β†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/aaron-he-zhu-paid-measurement-loop/audits/8?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/aaron-he-zhu-paid-measurement-loop/security.svg)](https://skillstore.io/skills/aaron-he-zhu-paid-measurement-loop?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/aaron-he-zhu-paid-measurement-loop?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/aaron-he-zhu-paid-measurement-loop/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/aaron-he-zhu-paid-measurement-loop.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA Β· BibTeX Β· CFF)

APA citation

aaron-he-zhu. (2026). paid-measurement-loop security audit report (audit version 8) [Author version 19.0.0]. Skillstore. https://skillstore.io/skills/aaron-he-zhu-paid-measurement-loop/audits/8

BibTeX citation

@techreport{aaron-he-zhu-aaron-he-zhu-paid-measurement-loop-2026, author = {aaron-he-zhu}, title = {paid-measurement-loop security audit report (audit version 8)}, institution = {Skillstore}, year = {2026}, number = {8}, url = {https://skillstore.io/skills/aaron-he-zhu-paid-measurement-loop/audits/8}, note = {Author version 19.0.0} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "paid-measurement-loop security audit report (audit version 8)" version: "19.0.0" type: report authors: - name: "aaron-he-zhu" date-released: "2026-07-27" url: "https://skillstore.io/skills/aaron-he-zhu-paid-measurement-loop/audits/8" identifiers: - type: other value: "skillstore:aaron-he-zhu-paid-measurement-loop:audit:8" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
100
Maintainability
87
Content
67
Community
91
Spec Compliance

What You Can Build

Review a budget increase

Compare performance after a budget change with an unchanged campaign over the same fixed window.

Assess new creative

Decide whether new creative should be promoted, tested longer, or rolled back using control-based evidence.

Prepare a stakeholder readback

Create a clear decision record with windows, controls, attribution notes, and measurement limitations.

Try These Prompts

Review one campaign change
Read back the budget increase for Campaign X. Compare ROAS with its unchanged control over the last 14 days.
Check creative performance
Evaluate the new prospecting creative against the prior creative. Use CPA as the primary metric and state the readback decision.
Compare platform results
Compare the attached Meta and Google exports. Normalize currency and attribution windows before assessing ROAS against each control.
Handle uncertain tracking
Review this campaign change and the conversion exports. Mark the result Unproven if duplicate orders or broken conversion tracking affects the evidence.

Best Practices

  • Fix the readback window and control before interpreting performance data.
  • Provide exports with dates, spend, conversions, revenue, attribution windows, and currency.
  • Label every figure as measured, user-provided, or estimated.

Avoid

  • Do not declare success from a raw before-and-after comparison without a control.
  • Do not compare platform ROAS before normalizing attribution windows and currency.
  • Do not make a decision while the campaign remains in learning phase or tracking is unreliable.

Frequently Asked Questions

What decision can this skill return?
It returns Promote, Keep-testing, Rollback, or Unproven for each campaign change.
What data do I need?
Provide your campaign export and, when available, analytics or ecommerce exports for the same window.
Can it use an advertising platform dashboard alone?
No. The skill asks for exports and does not estimate a readback from dashboard data alone.
Why is a control required?
A control helps separate the campaign change from market movement, seasonality, and other effects.
Does it calculate ROAS and CPA?
It delegates ratio and CPA arithmetic to roi-calculator, then applies the readback decision rule.
What happens when tracking is unreliable?
The skill marks the readback Unproven and identifies the repair needed before a new fixed window begins.

Developer Details

License

Apache-2.0

Author version

v19.0.0

Skillstore revision

r2

Ref

0715a6e09ea875c8e28cb705ce87cc83045e69c1

Maintenance freshness

7/28/2026

Usage

4 downloads Β· 0 views

File structure

πŸ“„ SKILL.md