ads

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a structured knowledge base and set of instructions for performance marketing tasks.
  • [EXTERNAL_DOWNLOADS]: The skill references tracking script templates and documentation from well-known and trusted services, including Google Ads, Meta (Facebook), LinkedIn, and TikTok. These are provided for informational purposes for the user to implement on their own web properties and do not involve the agent downloading or executing remote code.
  • [DATA_EXFILTRATION]: No indicators of credential harvesting or unauthorized data transfer were found. References to tracking pixels are standard industry practices for attribution and are documented neutrally.
  • [PROMPT_INJECTION]: No evidence of role-play, bypass markers, or attempts to override agent constraints was detected. The instructions focus entirely on campaign optimization and ad generation.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest context from local files such as .agents/product-marketing.md. This represents a standard surface for indirect prompt injection if the ingested data is attacker-controlled. However, the skill's primary capabilities are limited to text generation (ad copy and strategy), which minimizes the potential impact.
  • [COMMAND_EXECUTION]: No dangerous shell commands or subprocess calls are present in the skill instructions or reference files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 07:25 AM
Security Audit — agent-trust-hub — ads