Facebook/Meta Ads
Pass
Audited by Gen Agent Trust Hub on Mar 9, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: Potential for Indirect Prompt Injection. * Ingestion points: The skill ingests user-provided data from 'customers.csv' to create custom audiences. * Boundary markers: There are no explicit delimiters or instructions defined to prevent the agent from following commands embedded in the customer data files. * Capability inventory: The skill utilizes tools like 'meta_ads_create' and 'meta_audience' which have the authority to create and modify assets in external advertising accounts. * Sanitization: No validation or sanitization logic is described for the content of the processed data files.
- [NO_CODE]: The provided skill content consists exclusively of markdown documentation and YAML configurations; no executable scripts or code files were found.
Audit Metadata