skills/findbene/skills/ads-plan/Gen Agent Trust Hub

ads-plan

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions in SKILL.md contain directives that explicitly invite the agent to bypass its own rules and structure.
  • Evidence: Under the 'When NOT to use' section, the skill specifies: 'User explicitly asks for raw output without skill discipline -> respect override'. This directive instructs the agent to disregard the skill's discipline if a user requests it, which is a common characteristic of prompt injection bypasses.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface related to its data ingestion and file loading patterns.
  • Ingestion points: The agent determines which industry template to load from the assets/ directory based on the user-provided 'business type' (as described in SKILL.md and references/details.md).
  • Boundary markers: No boundary markers or instructions to sanitize or validate the user-supplied business type are present in the instructions.
  • Capability inventory: The skill is configured with Glob, Grep, and Read tools, which provide the capability to access the local filesystem.
  • Sanitization: There is no logic to prevent a user from supplying a path traversal string (e.g., '../../../etc/passwd') as the business type, which the agent might then attempt to load using its file-reading capabilities.
  • [NO_CODE]: The skill package does not include any executable code or scripts.
  • Evidence: All 14 provided files are in Markdown format (.md). The skill relies on natural language instructions to perform its tasks using the platform's native tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 02:12 AM
Security Audit — agent-trust-hub — ads-plan