ads-google
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of instructional content and auditing criteria for Google Ads (Search, PMax, Display, etc.) without any executable malicious code or suspicious logic.
- [EXTERNAL_DOWNLOADS]: The documentation references an optional integration with the official Google Ads MCP server (
github.com/googleads/google-ads-mcp). As this repository belongs to a trusted organization, the reference is considered safe. - [DATA_EXFILTRATION]: The skill mentions retrieving Customer IDs from local project documentation (
CLAUDE.md). This is a standard and safe practice for providing the agent with the necessary context to identify which advertising account to analyze. - [PROMPT_INJECTION]: The skill processes external data such as Search Terms Reports. While this presents a theoretical surface for indirect prompt injection, it is the primary intended function of the skill and no exploitable capability-chaining was detected.
Audit Metadata