21-ads-audit-global
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill iterates through ad campaign details, including names, search terms, and creative copy, which are external, untrusted inputs potentially containing malicious instructions.\n
- Ingestion points: Untrusted content enters the context via manual data entry, pasted tables, and automated data pulls from official Meta and Google MCP servers mentioned in
SKILL.md.\n - Boundary markers: Absent. The instructions do not define clear delimiters or provide the agent with directives to ignore instructions potentially embedded in the audited marketing data.\n
- Capability inventory: The skill is designed for analytical scoring and reporting; it does not request or demonstrate capabilities for arbitrary file writing or outgoing network requests beyond its defined tool scope.\n
- Sanitization: The skill lacks logic for sanitizing or validating campaign-derived strings before they are processed by the reasoning engine.
Audit Metadata