ad-account-diagnostic

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and interpret external data from advertising platforms and CRM systems, which presents a surface for indirect prompt injection.
  • Ingestion points: The skill collects user answers and external data exports (CSV/Excel/Spreadsheet) during the 'Interview' and 'Workflow' steps in SKILL.md.
  • Boundary markers: Robust boundaries are present through the 'Interview' phase (one question per message) and the 'Evidence Gate' (Workflow step 6), which requires specific data thresholds and lag maturity before proceeding.
  • Capability inventory: The skill is limited to diagnostic output and does not execute system commands, write files, or perform network operations. All findings across SKILL.md and referenced files are purely analytical.
  • Sanitization: The skill mitigates risks by requiring the user to perform manual data exports and applies specific mathematical formulas for decomposition, rather than processing raw strings directly.
  • [SAFE]: The skill maintains a strict boundary at the ad account level, explicitly handing off post-click issues to sibling skills. All referenced sibling skills (mbfinotti/advertising-skills@*) belong to the same vendor, indicating a cohesive and legitimate ecosystem of tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:32 PM
Security Audit — agent-trust-hub — ad-account-diagnostic