skills/johnefemer/skillfish/paid-ads/Gen Agent Trust Hub

paid-ads

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to read and follow instructions from a local file (.claude/product-marketing-context.md) to guide its campaign strategy. This creates an indirect prompt injection surface as the agent is not told to sanitize this input or treat it as untrusted data.
  • Ingestion points: .claude/product-marketing-context.md (referenced in SKILL.md).
  • Boundary markers: Absent. There are no delimiters or warnings to ignore potentially malicious instructions embedded within the marketing context.
  • Capability inventory: The skill is designed to interact with powerful advertising platform tools (Google Ads, Meta Ads, LinkedIn Ads, etc.) which typically have capabilities to modify account settings, budgets, and creative content.
  • Sanitization: No validation or filtering is performed on the content of the marketing context file before it is used to influence the agent's actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 04:18 PM
Security Audit — agent-trust-hub — paid-ads