ad-copy-generation
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection vulnerability surface detected.\n
- Ingestion points: The skill ingests untrusted data from landing pages via the
scrapeLandingPage(landingPageUrl)function inSKILL.md.\n - Boundary markers: The provided implementation logic lacks explicit delimiters or instructions to ignore embedded commands within the scraped landing page content.\n
- Capability inventory: The skill includes capabilities to generate ad copy and mentions deployment to Google Ads via the Buddy™ platform and architecture diagram.\n
- Sanitization: There is no evidence of content sanitization, escaping, or validation of the external landing page data before it is processed by the AI generation engine.
Audit Metadata