google-ads

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses the sensitive configuration file ~/.google-ads.yaml. This file is the standard location for storing Google Ads API credentials, including developer tokens and OAuth refresh tokens. While accessing these credentials is required for the skill's operation, they represent a sensitive data exposure surface.
  • [PROMPT_INJECTION]: The skill processes untrusted external data retrieved from the Google Ads UI and API, such as campaign names and keyword text. This constitutes an indirect prompt injection surface where malicious strings in an ad account could attempt to influence the agent's behavior during audits.
  • Ingestion points: Browser snapshots of ads.google.com and API search results from the GoogleAdsService (documented in SKILL.md and references/api-setup.md).
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are utilized to separate external data from system prompts.
  • Capability inventory: The skill allows the agent to execute Python code, pause keywords, and modify campaign budgets based on its analysis of the account data.
  • Sanitization: No explicit sanitization or filtering of external campaign or keyword content is performed before processing.
  • [COMMAND_EXECUTION]: The skill executes shell commands to verify the existence of configuration files (ls ~/.google-ads.yaml) and check the local Python environment for necessary SDKs.
  • [REMOTE_CODE_EXECUTION]: The skill relies on the official google-ads Python package. This is the well-known and trusted SDK provided by Google for API interactions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 01:06 PM
Security Audit — agent-trust-hub — google-ads