google-ads-manager
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted external data, which could potentially contain malicious instructions targeted at the agent.
- Ingestion points: The
weekly_tasksandmonthly_taskssections inSKILL.mdinstruct the agent toreview_search_termsand performcompetitor_analysisby analyzing external ad copy and search queries. - Boundary markers: No specific delimiters or instructional guardrails are defined in the templates to differentiate between data and instructions when the agent processes search term reports.
- Capability inventory: The skill utilizes tools such as
google_ads_createandgoogle_ads_report, providing the agent with the ability to modify campaign settings based on the data it processes. - Sanitization: There are no explicit sanitization or validation steps provided for the external strings retrieved from the Google Ads API before they are processed by the agent.
Audit Metadata