ads-google

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and analyze external data such as Search Terms Reports and Change History. This creates a surface for indirect prompt injection, where malicious instructions could be embedded within the ad data (e.g., campaign names or search queries) to manipulate the agent's output or behavior.
  • Ingestion points: Processes Google Ads account data, Search Terms Reports, and Change History provided as external exports or via MCP.
  • Boundary markers: The skill does not define explicit boundary markers or provide instructions to the agent to disregard natural language commands found within the ad data.
  • Capability inventory: The skill reads local reference files and suggests the use of Google Ads MCP tools (search, list_accessible_customers) for data retrieval.
  • Sanitization: There is no evidence of sanitization or validation of the ingested external data strings before they are processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill references an official Google Ads MCP server repository (github.com/googleads/google-ads-mcp) for automated data collection. This is a reference to a well-known service provided by Google for account management and does not constitute a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 06:41 PM
Security Audit — agent-trust-hub — ads-google