conversion-debug

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external tracking and advertising platforms (Google Tag Manager, Google Analytics 4, Meta Ads) using MCP tools and interacts with the local system via bash and file operations.
  • Ingestion points: Data retrieved from third-party APIs via mcp__cogny__* tools (tag names, trigger configurations, and report data).
  • Boundary markers: Absent; the instructions do not define specific delimiters to separate untrusted tool output from internal logic.
  • Capability inventory: Access to Bash for command execution, Write for file modification, and WebFetch for network operations.
  • Sanitization: No explicit instructions are provided to sanitize or validate data returned from external platforms before processing it or using it in system commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:42 PM