google-ads-scripts

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill includes code patterns for using UrlFetchApp.fetch to check URL status and MailApp.sendEmail for reporting. These are standard capabilities for Google Ads Scripts and are used here with placeholders for sensitive destinations, representing no immediate risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest user-supplied topics or code snippets for debugging and optimization. While this creates a processing surface for untrusted data, the capabilities are appropriately scoped to the developer-assistant use case.
  • Ingestion points: <script pattern or topic> argument and user questions.
  • Boundary markers: Not explicitly defined in instructions.
  • Capability inventory: WebSearch, Read, Write, Bash, and vendor-specific Google Ads tools.
  • Sanitization: None performed on the technical input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:41 PM