Stop tracker agents from inventing vendors
The identification agent attributed probo_distinct_id to Mixpanel purely on the shared distinct_id token, and the enrichment agent returned no description for the glob ph_phc_*_posthog because it searched the literal "*" string and found nothing. Tighten the identification prompt so attribution requires a perfect pattern match or a meaningful prefix that belongs to the vendor; a generic token behind a different prefix is not a match. Teach the enrichment prompt to strip wildcard and variable parts before searching, and to treat a vendor name embedded in the key as corroboration so clearly-named trackers still get a description. Signed-off-by: Émile Ré <emile@probo.com>
This commit is contained in:
@@ -12,16 +12,18 @@ Return a structured JSON response with:
|
||||
<instructions>
|
||||
1. Use the search_third_parties tool to confirm details about the operating company when one is associated with this tracker.
|
||||
|
||||
2. Use web_search to find authoritative information about the tracker's purpose. Try up to 3 targeted queries, adapting to the available signals:
|
||||
- With a recognizable prefix or name: "[name] cookie purpose" (e.g. "_ga cookie purpose").
|
||||
- For localStorage keys: "[name] localStorage purpose tracking".
|
||||
- Broaden if needed: "[name] cookie what is it used for".
|
||||
2. Patterns are often aggregated globs: variable parts (IDs, UUIDs, timestamps, project keys) are collapsed into a "*" wildcard (e.g. "ph_phc_*_posthog", "_gat_UA-*"). Before searching, strip the wildcard and any variable parts and search the fixed prefix/root plus any vendor token embedded in the name — never search the literal "*". For "ph_phc_*_posthog", search "ph_ posthog localStorage purpose", not "ph_phc_*_posthog".
|
||||
|
||||
3. Use web_search to find authoritative information about the tracker's purpose. Try up to 3 targeted queries, adapting to the available signals:
|
||||
- With a recognizable prefix or name: "[prefix] cookie purpose" (e.g. "_ga cookie purpose").
|
||||
- For localStorage keys: "[prefix] localStorage purpose tracking".
|
||||
- Broaden if needed: "[prefix] cookie what is it used for".
|
||||
- Stop once you have a confident, well-sourced answer; do not exhaust all queries if the first succeeds.
|
||||
- Verify that any result discusses a tracker whose name shares a meaningful prefix with the pattern being described. Discard results about a differently-named tracker.
|
||||
- Verify that any result discusses a tracker whose name shares a meaningful prefix with the pattern being described. Discard results about a differently-named tracker. A generic token shared with a vendor's terminology (e.g. distinct_id, session, uid) is NOT a match when it sits behind a different, meaningful prefix — the leading prefix attributes the vendor, not a common word elsewhere in the name.
|
||||
|
||||
3. Be factual and conservative. Describe only what the evidence supports. Do not speculate about data flows or purposes you cannot substantiate.
|
||||
4. Be factual and conservative. Describe only what the evidence supports. Do not speculate about data flows or purposes you cannot substantiate. The supplied third party is corroborated when the tracker's meaningful prefix belongs to that vendor, when the vendor's name is embedded in the key (e.g. "posthog" in "ph_phc_*_posthog"), or by a perfect pattern match; in those cases name the vendor and describe its purpose. Only when none of those hold — the vendor rests on a shared generic word alone — withhold the vendor name and describe just what you can substantiate, or return an empty description.
|
||||
|
||||
4. Keep the description concise (one to two sentences) and free of marketing language. It should read as a neutral, compliance-grade statement of purpose.
|
||||
5. Keep the description concise (one to two sentences) and free of marketing language. It should read as a neutral, compliance-grade statement of purpose.
|
||||
|
||||
5. If you genuinely cannot substantiate the tracker's purpose from evidence, return an empty description. Do not write a fallback such as "purpose could not be determined", and do not guess a purpose from the name or max-age alone (e.g. do not claim a key is "used for session" just because it has no expiry). An empty description is preferable to an unverified one.
|
||||
6. If you genuinely cannot substantiate the tracker's purpose from evidence, return an empty description. Do not write a fallback such as "purpose could not be determined", and do not guess a purpose from the name or max-age alone (e.g. do not claim a key is "used for session" just because it has no expiry). An empty description is preferable to an unverified one.
|
||||
</instructions>
|
||||
|
||||
Reference in New Issue
Block a user