ad-performance-loop

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8) due to how it processes external data.
  • Ingestion points: Data is ingested in Step 1 from external ad platforms (Meta, TikTok, Google) and potentially via postgres MCP queries. Fields like 'Hook' and 'Angle' are populated with external content.
  • Boundary markers: Absent. While the skill uses structured Markdown templates for data representation, it does not include explicit instructions or delimiters to prevent the agent from following instructions that might be embedded within the creative text (e.g., a malicious hook string).
  • Capability inventory: The skill can write to persistent storage via memory MCP and triggers downstream actions by generating a 'Regeneration Brief' for the ad-script-generator skill.
  • Sanitization: Absent. There is no evidence of sanitization, escaping, or validation of the creative text before it is analyzed or passed to the regeneration and memory storage steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:07 PM
Security Audit — agent-trust-hub — ad-performance-loop