03-performance-eval-global
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources, including user-provided marketing metrics and automated data pulls from various Model Context Protocol (MCP) servers.
- Ingestion points: Gathered via user queries (spend, impressions, clicks, etc.) and tool outputs from Meta, Google, and TikTok MCP servers as described in
SKILL.md. - Boundary markers: The instructions do not define specific delimiters (e.g., XML tags or triple quotes) to separate untrusted external data from the agent's internal logic.
- Capability inventory: The skill's primary function is generating text-based diagnostic reports and action plans. It does not exhibit dangerous capabilities such as arbitrary file writes, shell command execution, or unauthorized network exfiltration.
- Sanitization: No evidence of input validation or sanitization for the marketing data is present in the skill instructions.
- [EXTERNAL_DOWNLOADS]: The skill recommends the integration of several external MCP servers for automated data retrieval.
- Evidence: References Meta Official MCP, Pipeboard, brijr/meta-mcp, Google Official MCP, AdsMCP/tiktok-ads-mcp-server, and Adspirer ads-mcp in
SKILL.md. These references target established marketing technology services and official platform integrations.
Audit Metadata