ads-linkedin
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for Indirect Prompt Injection by ingesting and processing data from external sources (LinkedIn Campaign Manager exports).
- Ingestion points: The skill instructions explicitly state the collection and processing of 'LinkedIn Ads data (Campaign Manager export)' in the Process section.
- Boundary markers: There are no specified delimiters or instructions to the agent to ignore or isolate instructions potentially embedded within the ad data exports.
- Capability inventory: The skill is capable of reading local reference files (e.g., 'ads/references/linkedin-audit.md') and generating output files (e.g., 'LINKEDIN-ADS-REPORT.md'). While it mentions CRM integration, no explicit network tool calls are defined in the provided markdown.
- Sanitization: The instructions lack any requirement for sanitizing, escaping, or validating the content of the ingested ad data before the agent processes it.
Audit Metadata