Facebook/Meta Ads

Pass

Audited by Gen Agent Trust Hub on Mar 9, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: Potential for Indirect Prompt Injection. * Ingestion points: The skill ingests user-provided data from 'customers.csv' to create custom audiences. * Boundary markers: There are no explicit delimiters or instructions defined to prevent the agent from following commands embedded in the customer data files. * Capability inventory: The skill utilizes tools like 'meta_ads_create' and 'meta_audience' which have the authority to create and modify assets in external advertising accounts. * Sanitization: No validation or sanitization logic is described for the content of the processed data files.
  • [NO_CODE]: The provided skill content consists exclusively of markdown documentation and YAML configurations; no executable scripts or code files were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 9, 2026, 08:21 AM
Security Audit — agent-trust-hub — Facebook/Meta Ads