data-manager-api-event-ingestion
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- Remote Resource Integration: The skill references official Google documentation and GitHub repositories to provide developers with implementation guides and code samples. These references are directed to established, official sources associated with the API provider.\n- Data Ingestion Surface: The skill involves constructing API requests based on user-provided event data and identifiers. This represents an indirect prompt injection surface where untrusted data enters the agent context. However, the risk is mitigated by the skill's instructions to use specific utility libraries for data processing and the inherent constraints of the structured API request format.\n- PII Handling Recommendations: A security consideration for event ingestion is the handling of Personally Identifiable Information (PII). The skill addresses this by recommending the use of the
google.ads.datamanager_utillibrary to format and hash identifiers like email addresses and phone numbers before transmission, which aligns with security best practices for data privacy.
Audit Metadata