thought-leadership-ads

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists exclusively of Markdown documentation and instructional logic. No executable scripts, binaries, or package manager configuration files (e.g., package.json or requirements.txt) are present.
  • [SAFE]: The skill references other modular tools within the author's namespace (e.g., mbfinotti/advertising-skills@ad-copy-variants) to delegate specific planning tasks. These are legitimate internal references used for task handoffs within the agent's environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an interview process that ingests untrusted user data (business model, budget details, etc.). However, since the skill's only capability is generating a text-based campaign plan and it lacks the ability to execute code, write to the filesystem, or perform network operations, this surface does not present a security risk.
  • Ingestion points: User responses to the "Interview" section in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: None (the skill only produces a text document).
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:32 PM
Security Audit — agent-trust-hub — thought-leadership-ads