amazon-ads

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: Instructions focus on operational precision and user consent. No bypass or system prompt extraction attempts detected. The skill includes a 'Safety Rules' section that enforces user-in-the-loop verification. It also addresses indirect injection risks through a mandatory pre-creation summary and approval phase (Phase 4). Ingestion points include profile and campaign listings, while capability tools are limited to the Amazon Ads API surface with strict sanitization (uppercase enums, specific date formats).
  • [DATA_EXFILTRATION]: No unauthorized data transfer or sensitive file access was found. Interactions are limited to authorized Amazon Ads tool calls. URL references target the vendor's official domain for legitimate integration setup.
  • [EXTERNAL_DOWNLOADS]: The skill does not perform remote script execution or install external packages. External links are informational and point to official setup pages.
  • [COMMAND_EXECUTION]: No shell access, system modification, or privilege escalation attempts. The skill operates strictly within the defined API tool surface.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets, tokens, or API keys are present. The skill correctly directs users to manage integrations through a dedicated secure application interface.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 04:20 AM