paid-ads
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions explicitly direct the agent to read
.claude/product-marketing-context.mdbefore proceeding. This creates a surface where malicious instructions could be embedded in the product context file to influence agent behavior. - Ingestion points: Reading of
.claude/product-marketing-context.md(SKILL.md, SKILL.en.md, SKILL.es.md). - Boundary markers: Absent. There are no instructions to treat the content of this file as untrusted or to ignore embedded commands.
- Capability inventory: The skill claims the persona has "direct access to ad platform accounts" and references tools for Google Ads, Meta, and LinkedIn for implementation.
- Sanitization: Absent. The agent is instructed to use the context directly to minimize questioning.
Audit Metadata