google-search-ads-builder

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious code, obfuscation, or unauthorized data access patterns were detected. The skill implements a structured workflow for marketing data generation.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes an attack surface for indirect prompt injection as it processes untrusted data from the web.
  • Ingestion points: Competitor websites and search results fetched via web_search and fetch_webpage in Phase 1B and 1C.
  • Boundary markers: Absent. The skill does not explicitly use delimiters or instructions to ignore embedded commands in the fetched content.
  • Capability inventory: The skill can perform web searches, fetch webpages, and write results to markdown and CSV files. It lacks high-risk capabilities like shell command execution or access to sensitive local credentials.
  • Sanitization: None observed for the external content before it is used in ad copy generation or strategy documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 02:25 PM