source-company-existing-ads
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill package is composed entirely of markdown documentation, workflow outlines, and test plan templates. It does not include any executable code, scripts, or binary files that could be run on a host system.
- [INDIRECT_PROMPT_INJECTION]: The workflow describes the ingestion of user-provided briefs and source asset paths, which represents a potential attack surface for indirect prompt injection.
- Ingestion points: User briefs and asset paths mentioned in the workflow of
SKILL.mdandtests/sample-input.md. - Boundary markers: The documentation does not specify any delimiters or instructions for the agent to distinguish between its primary instructions and content within the external data.
- Capability inventory: No execution capabilities (such as shell access, file writes, or network calls) are present in the skill's current documentation-only form.
- Sanitization: There is no evidence of input validation or sanitization logic in the provided files.
Audit Metadata