ads-google
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and analyze external data such as Search Terms Reports and Change History. This creates a surface for indirect prompt injection, where malicious instructions could be embedded within the ad data (e.g., campaign names or search queries) to manipulate the agent's output or behavior.
- Ingestion points: Processes Google Ads account data, Search Terms Reports, and Change History provided as external exports or via MCP.
- Boundary markers: The skill does not define explicit boundary markers or provide instructions to the agent to disregard natural language commands found within the ad data.
- Capability inventory: The skill reads local reference files and suggests the use of Google Ads MCP tools (
search,list_accessible_customers) for data retrieval. - Sanitization: There is no evidence of sanitization or validation of the ingested external data strings before they are processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill references an official Google Ads MCP server repository (github.com/googleads/google-ads-mcp) for automated data collection. This is a reference to a well-known service provided by Google for account management and does not constitute a security risk.
Audit Metadata