ad-manager

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill processes untrusted external data from CSV reports, ad platform connectors (TikTok, Google Ads), and CRM systems (HubSpot). This represents a surface where malicious instructions could be embedded in data fields to attempt to override agent behavior.
  • Ingestion points: Ad performance metrics in CSV exports, TikTok Ads connector data, HubSpot CRM records, and landing page content retrieved via WebFetch.
  • Boundary markers: The skill includes an explicit "What not to do" section instructing the agent to ignore instructions found inside processed data and refers to a shared untrusted-content.md safety protocol.
  • Capability inventory: The skill has the ability to execute budget changes, pause or restart campaigns, and publish new advertisements in connected ad accounts, which are sensitive operations gated by user approval.
  • Sanitization: The instructions explicitly mandate that message, ticket, and document text must be treated as data about the sender rather than commands, and requires an explicit "yes" from the owner before any financial changes are executed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:06 PM
Security Audit — agent-trust-hub — ad-manager