google-ads-copy

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is focused on generating Responsive Search Ad (RSA) assets and managing creative experiments. The instructions align with the stated purpose and follow advertising best practices.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads business context and persona-specific data from the local file system ({data_dir}/business-context.json, {data_dir}/personas/{accountId}.json). This is a standard pattern for providing the agent with the necessary background information to generate relevant ad copy.
  • [COMMAND_EXECUTION]: The skill utilizes specialized tools such as runScript with ads.gaqlParallel and experiment management tools (createAdVariationExperiment, createExperiment). These operations are scoped to the Google Ads API environment and are used to retrieve performance metrics or manage ad variations.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface via the ingestion of external JSON data and user input. However, it incorporates significant safeguards, including a mandatory "Copy output contract" that requires a decision record and a non-negotiable requirement for explicit user confirmation of all proposed assets, character counts, and pin positions before deployment.
  • [SAFE]: The skill references internal documentation for best practices and benchmarks, which is a safe and recommended practice for maintaining consistency and compliance in ad copy generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:14 PM
Security Audit — agent-trust-hub — google-ads-copy