demand-gen-audit

Pass

Audited by Gen Agent Trust Hub on May 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill operates within its defined scope to perform advertising audits. All tools and external references are consistent with the author's stated identity and purpose. No suspicious command execution, hardcoded credentials, or persistence mechanisms were detected.- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by processing external data from Google Ads campaign and ad group names.
  • Ingestion points: Data retrieved via the GAQL execution tools (campaign.name, ad_group.name).
  • Boundary markers: Absent.
  • Capability inventory: Includes the ability to record findings via mcp__cogny__create_finding and perform web searches.
  • Sanitization: Not explicitly defined in the instruction markdown.
Audit Metadata
Risk Level
SAFE
Analyzed
May 28, 2026, 03:46 PM
Security Audit — agent-trust-hub — demand-gen-audit