paid-measurement-loop

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts, specifically ledger.py and experiment.py, to perform statistical analysis and maintain a ledger of campaign changes. These scripts are referenced via ${CLAUDE_PLUGIN_ROOT}, indicating they are bundled with the skill package.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources, such as campaign CSV exports from ad platforms and ecommerce systems. It identifies this attack surface and mitigates it by instructing the agent to treat every fetched or exported file as untrusted input and to ignore any instructions embedded within them, using them strictly as data.
  • [EXTERNAL_DOWNLOADS]: Mentions optional connectivity to well-known marketing services like Google Ads and Meta Marketing APIs. These are recognized as legitimate well-known services and are used for data retrieval at the user's discretion.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 07:29 PM
Security Audit — agent-trust-hub — paid-measurement-loop