meta-ads-analyzer

Pass

Audited by Gen Agent Trust Hub on May 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill enforces strict terminology and metric naming conventions required by Meta's official policies, which helps prevent data misrepresentation and ensures legal compliance.
  • [DATA_EXPOSURE]: The skill instructions emphasize data integrity, specifically regarding currency conversion, date handling, and the prevention of data fabrication by enforcing 'N/A' or 'Data not available' for null values instead of allowing the model to hallucinate or estimate.
  • [INDIRECT_PROMPT_INJECTION]: As an analysis skill, it ingests data from external sources (Meta Ads API via MCP tools). While it has the standard attack surface for processing untrusted external content (e.g., ad copy or campaign names), the prompt includes multiple constraints and mandatory terminology rules that serve as implicit guardrails against instruction overrides embedded in the data.
  • [REMOTE_CODE_EXECUTION]: No remote code execution or external script downloads were detected. The skill uses standardized tool calls (MCP) within the agent's environment.
  • [SAFE]: The skill provides a clear 'Special handling' section for sensitive topics like advertising policies, ensuring the agent routes users to official documentation rather than interpreting rules itself.
Audit Metadata
Risk Level
SAFE
Analyzed
May 26, 2026, 10:52 AM
Security Audit — agent-trust-hub — meta-ads-analyzer