paid-ads
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions advise the agent to request and analyze external content like landing page URLs and customer lists, creating a potential vector for indirect prompt injection if the external sources contain malicious instructions. \n
- Ingestion points: The agent is prompted to ask for 'landing page URL' and 'existing customer data' in the 'Before Starting' phase. \n
- Boundary markers: The skill lacks delimiters or instructions for the agent to disregard commands embedded in external content. \n
- Capability inventory: The skill body contains no code, but the agent persona assumes 'direct access to ad platform accounts'. \n
- Sanitization: The instructions do not include steps for sanitizing or validating the content of the provided URLs or data.
Audit Metadata