pp-stackadapt

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the stackadapt-pp-cli binary from vendor-controlled repositories using go install and npx. These resources originate from the identified author/vendor.
  • [DATA_EXFILTRATION]: The CLI tool features a --deliver webhook:<url> argument. This capability allows command outputs, which may contain sensitive advertising metrics or campaign details, to be transmitted to an arbitrary external URL.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes and displays untrusted data fetched from the StackAdapt API.
  • Ingestion points: Campaign data and delivery reports retrieved through commands such as pacing, delivery-drift, and report in SKILL.md.
  • Boundary markers: None; the skill instructions do not define delimiters or provide specific guidance to the agent to disregard instructions embedded in the API data.
  • Capability inventory: The skill has access to shell command execution via the Read Bash tool.
  • Sanitization: There is no documented validation or sanitization of data returned by the API before it is added to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 10:21 AM
Security Audit — agent-trust-hub — pp-stackadapt