meta-ads-campaign-builder

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection due to its processing of untrusted external data.
  • Ingestion points: Data from web_search, meta-ad-scraper, and user-provided URLs is ingested into the agent context in SKILL.md.
  • Boundary markers: No delimiters or instructions are used to distinguish external data from core instructions.
  • Capability inventory: The skill can write files to the local filesystem, specifically saving markdown campaign plans to the clients directory as described in SKILL.md.
  • Sanitization: Content retrieved from tools is not sanitized or validated before being used in output generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 02:50 AM