ad-spend-allocation

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists entirely of Markdown instructions, reference documents, and JSON evaluation files. There are no executable scripts (Python, JavaScript, shell, etc.) included in the package.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-supplied advertising performance data (spend, conversion lag, platform-reported ROAS). While it lacks explicit boundary markers for this data, the risk is negligible because the skill does not possess capabilities for file writing, network communication, or system command execution.
  • [SAFE]: The content demonstrates a high degree of data integrity. In the references/heuristics-and-figure-grading.md file, the author explicitly identifies commonly fabricated or folkloric marketing statistics (such as non-existent McKinsey reports) and instructs the agent never to repeat them as fact.
  • [SAFE]: The skill restricts its logic to strategic advice and calculation, explicitly stating that it recommends but never executes platform changes, which maintains a safe boundary between analysis and account modification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:32 PM
Security Audit — agent-trust-hub — ad-spend-allocation