competitive-ads-extractor
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill involves processing untrusted data from external sources, which constitutes an attack surface for indirect prompt injection.\n- Ingestion points: Competitor ad copy, creative descriptions, and metadata are scraped from the Facebook Ad Library and LinkedIn (SKILL.md).\n- Boundary markers: The documentation does not define specific delimiters or instructions to ignore embedded commands within the scraped content.\n- Capability inventory: The agent captures screenshots and writes analysis files to the local filesystem (e.g.,
~/competitor-ads/).\n- Sanitization: There is no mention of text sanitization or validation of the extracted ad content.\n- Risk: Malicious instructions hidden in ad text or metadata could attempt to hijack the agent's reasoning or influence its output to the user.\n- [NO_CODE]: The skill package contains only markdown instructions and no executable scripts, packages, or system configuration files.
Audit Metadata