ads-linkedin

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for Indirect Prompt Injection by ingesting and processing data from external sources (LinkedIn Campaign Manager exports).
  • Ingestion points: The skill instructions explicitly state the collection and processing of 'LinkedIn Ads data (Campaign Manager export)' in the Process section.
  • Boundary markers: There are no specified delimiters or instructions to the agent to ignore or isolate instructions potentially embedded within the ad data exports.
  • Capability inventory: The skill is capable of reading local reference files (e.g., 'ads/references/linkedin-audit.md') and generating output files (e.g., 'LINKEDIN-ADS-REPORT.md'). While it mentions CRM integration, no explicit network tool calls are defined in the provided markdown.
  • Sanitization: The instructions lack any requirement for sanitizing, escaping, or validating the content of the ingested ad data before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 06:41 PM
Security Audit — agent-trust-hub — ads-linkedin