03-danh-gia-hieu-suat
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions reference external Model Context Protocol (MCP) servers to automate data retrieval, including Meta's official ads MCP (mcp.facebook.com/ads) and Pipeboard (mcp.pipeboard.co/meta-ads-mcp). These connections are documented for legitimate marketing performance analysis purposes and target well-known platforms.
- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates an attack surface for indirect prompt injection due to its core function of processing untrusted external data.
- Ingestion points: External data is ingested through several Meta-specific and platform-agnostic MCP tools (e.g., ads_insights_anomaly_signal, ads_insights_industry_benchmark) and manual user input regarding campaign performance.
- Boundary markers: The instructions lack explicit delimitation or instructions for the agent to ignore potential instructions embedded within the retrieved advertising data.
- Capability inventory: The skill's capabilities include reading external data and generating markdown files for diagnostic analysis; it does not possess high-risk capabilities like arbitrary shell execution or persistence.
- Sanitization: There are no documented steps for validating, sanitizing, or filtering the content of the data fetched from the external advertising platforms before processing.
Audit Metadata