21-ads-audit-global

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the processing of external ad account data.
  • Ingestion points: The agent is instructed to ingest and analyze data from ad platforms, including campaign names, ad set titles, and search term reports which are partially controlled by external users or the account owner (SKILL.md, variants/01-us.md).
  • Boundary markers: The instructions do not implement specific delimiters or 'ignore embedded instructions' markers to isolate external data from the system prompt.
  • Capability inventory: The skill uses tools to fetch insights and metrics (e.g., ads_insights_anomaly_signal, GAQL queries) but does not have the capability to write to the file system or execute arbitrary shell commands.
  • Sanitization: No sanitization or validation logic is present to filter malicious instructions embedded within the processed ad metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 03:31 PM
Security Audit — agent-trust-hub — 21-ads-audit-global