paidads
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill architecture handles untrusted external data which could lead to manipulation of agent instructions.\n
- Ingestion points: Data enters the context via the
web_fetchtool when analyzing landing pages (referenced inreferences/linkedin.md) and through user-provided account exports, screenshots, and CRM data during theauditmode.\n - Boundary markers: The instructions in
SKILL.mdand the reference playbooks do not contain explicit delimiters or 'ignore' instructions to separate processed data from command execution context.\n - Capability inventory: The skill is configured in
agents/openai.yamlwith broad tool access includingbash,run_command,write_to_file,replace_file_content, andweb_fetch.\n - Sanitization: There are no documented procedures for sanitizing or validating external content before it is ingested and acted upon by the agent.\n- [DATA_EXFILTRATION]: The skill is designed to manage sensitive business and marketing data.\n
- Sensitive data handling: The skill interacts with campaign budgets, lead-generation data (PII), and conversion tracking metrics across multiple platforms.\n
- Exfiltration risk: The combination of access to sensitive account information and the ability to perform network operations via
web_fetchcreates a theoretical risk for data exfiltration if the agent is compromised by malicious external content.
Audit Metadata