21-ads-audit-global
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill functions as a set of instructions and benchmarks for advertising audits. Analysis revealed no malicious patterns, unauthorized data exfiltration, or credential exposure.
- [NO_CODE]: The skill consists of Markdown files and does not include any executable scripts, which eliminates risks associated with dynamic code execution or privilege escalation.
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface. 1. Ingestion points: Ad platform metadata (campaign/ad names) ingested via MCP or manual input (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Data analysis and report generation; no shell or file-write capabilities detected in the provided files. 4. Sanitization: Absent. Severity is low as the skill lacks high-impact tools.
- [EXTERNAL_DOWNLOADS]: The skill mentions external Model Context Protocol (MCP) servers for data access. These references target well-known and official platforms (Meta, Google) and are categorized as safe for the intended auditing purpose.
Audit Metadata