ads-setup
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements strict secret management policies, instructing the agent to never store or commit API keys, tokens, or passwords, and instead use environment variables or keychains.- [SAFE]: The instructions explicitly forbid remote pipe-to-shell installation patterns (e.g.,
curl | bash), directing the agent to use verified local checkouts and checksum verification.- [SAFE]: The skill incorporates defensive measures against indirect prompt injection by mandating that websites and uploaded materials be treated as untrusted data.
Audit Metadata