21-ads-audit-global

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill iterates through ad campaign details, including names, search terms, and creative copy, which are external, untrusted inputs potentially containing malicious instructions.\n
  • Ingestion points: Untrusted content enters the context via manual data entry, pasted tables, and automated data pulls from official Meta and Google MCP servers mentioned in SKILL.md.\n
  • Boundary markers: Absent. The instructions do not define clear delimiters or provide the agent with directives to ignore instructions potentially embedded in the audited marketing data.\n
  • Capability inventory: The skill is designed for analytical scoring and reporting; it does not request or demonstrate capabilities for arbitrary file writing or outgoing network requests beyond its defined tool scope.\n
  • Sanitization: The skill lacks logic for sanitizing or validating campaign-derived strings before they are processed by the reasoning engine.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:39 PM
Security Audit — agent-trust-hub — 21-ads-audit-global