03-performance-eval-global

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources, including user-provided marketing metrics and automated data pulls from various Model Context Protocol (MCP) servers.
  • Ingestion points: Gathered via user queries (spend, impressions, clicks, etc.) and tool outputs from Meta, Google, and TikTok MCP servers as described in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters (e.g., XML tags or triple quotes) to separate untrusted external data from the agent's internal logic.
  • Capability inventory: The skill's primary function is generating text-based diagnostic reports and action plans. It does not exhibit dangerous capabilities such as arbitrary file writes, shell command execution, or unauthorized network exfiltration.
  • Sanitization: No evidence of input validation or sanitization for the marketing data is present in the skill instructions.
  • [EXTERNAL_DOWNLOADS]: The skill recommends the integration of several external MCP servers for automated data retrieval.
  • Evidence: References Meta Official MCP, Pipeboard, brijr/meta-mcp, Google Official MCP, AdsMCP/tiktok-ads-mcp-server, and Adspirer ads-mcp in SKILL.md. These references target established marketing technology services and official platform integrations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:39 PM
Security Audit — agent-trust-hub — 03-performance-eval-global