03-danh-gia-hieu-suat

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions reference external Model Context Protocol (MCP) servers to automate data retrieval, including Meta's official ads MCP (mcp.facebook.com/ads) and Pipeboard (mcp.pipeboard.co/meta-ads-mcp). These connections are documented for legitimate marketing performance analysis purposes and target well-known platforms.
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates an attack surface for indirect prompt injection due to its core function of processing untrusted external data.
  • Ingestion points: External data is ingested through several Meta-specific and platform-agnostic MCP tools (e.g., ads_insights_anomaly_signal, ads_insights_industry_benchmark) and manual user input regarding campaign performance.
  • Boundary markers: The instructions lack explicit delimitation or instructions for the agent to ignore potential instructions embedded within the retrieved advertising data.
  • Capability inventory: The skill's capabilities include reading external data and generating markdown files for diagnostic analysis; it does not possess high-risk capabilities like arbitrary shell execution or persistence.
  • Sanitization: There are no documented steps for validating, sanitizing, or filtering the content of the data fetched from the external advertising platforms before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:39 PM
Security Audit — agent-trust-hub — 03-danh-gia-hieu-suat