ad-conversion-tracking

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external data from advertising platforms, tag managers, and CRMs. While this creates a theoretical attack surface, it is a functional requirement for verifying tracking accuracy, and no malicious patterns were identified.
  • Ingestion points: Tag debug outputs, network payloads, platform UI statuses, and CRM records in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: None. The skill provides observational and procedural instructions without automated scripts, file system writes, or dangerous tool invocations.
  • Sanitization: Absent.
  • [SAFE]: The skill references other advertising-related skills within the 'mbfinotti' vendor namespace, which is consistent with the author's context and represents normal modular functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:32 PM
Security Audit — agent-trust-hub — ad-conversion-tracking