google-search-ads-builder
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious code, obfuscation, or unauthorized data access patterns were detected. The skill implements a structured workflow for marketing data generation.
- [INDIRECT_PROMPT_INJECTION]: The skill includes an attack surface for indirect prompt injection as it processes untrusted data from the web.
- Ingestion points: Competitor websites and search results fetched via
web_searchandfetch_webpagein Phase 1B and 1C. - Boundary markers: Absent. The skill does not explicitly use delimiters or instructions to ignore embedded commands in the fetched content.
- Capability inventory: The skill can perform web searches, fetch webpages, and write results to markdown and CSV files. It lacks high-risk capabilities like shell command execution or access to sensitive local credentials.
- Sanitization: None observed for the external content before it is used in ad copy generation or strategy documents.
Audit Metadata