meta-ads
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: Fetches and manages ad data through the official Meta Graph API at graph.facebook.com, a well-known technology service.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external ad accounts (ad names, creative copy) via the Meta API (graph.facebook.com) as seen in scripts/meta_client.py. While it lacks explicit boundary markers or sanitization for this content, the risk is mitigated by the requirement for human-in-the-loop confirmation before any modification is written back to the API. The skill possesses capabilities for network operations (meta_client.py) and local file writing (exchange_token.py).
Audit Metadata