ads
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a local utility script
scripts/verify.shintended for linting ad plans and creative assets. The script uses standard Unix utilities (find,grep,sed,awk) to verify character counts and ROAS math. Analysis of the script confirms it implements proper input sanitization using regular expressions to filter data before processing, mitigating command injection risks.- [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it is designed to ingest and process data from local project files (e.g., ad plans, creative copy). - Ingestion points: The
scripts/verify.shscript scans and reads content from*.md,*.txt,*.yaml,*.yml, and*.csvfiles within the target directory. - Boundary markers: The processing logic does not utilize specific boundary markers or 'ignore' instructions for the data being parsed, though it relies on specific tags like
[PMAX-HEADLINE]or[ROAS]. - Capability inventory: The skill allows for local file reading and shell script execution via
scripts/verify.sh. - Sanitization: The linter script employs strict
sedpatterns to extract numeric values and labels, which serves as a functional sanitization layer against malicious payloads in the data files.
Audit Metadata