google-ads
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill accesses the sensitive configuration file
~/.google-ads.yamland includes instructions to display its contents (cat ~/.google-ads.yaml) to the agent's context. This file contains highly sensitive information including developer tokens and OAuth secrets. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content such as campaign names and keyword text which are then used to inform and execute mutation commands.
- Ingestion points: Fetches campaign and keyword data via the Google Ads API and browser snapshots from
ads.google.com. - Boundary markers: Absent; the skill does not use delimiters to isolate external data from instructions.
- Capability inventory: Possesses capabilities to pause campaigns, pause keywords, and update budgets.
- Sanitization: No sanitization or validation of external strings is performed before they influence decision-making or command execution.
Audit Metadata