meta-ads

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the runScript tool to execute complex data correlations and parallel API requests to the Meta Graph API. This is standard for advertising analytics.
  • [DYNAMIC_EXECUTION]: The skill requires the agent to generate and run scripts locally for processing advertising metrics.
  • [DATA_EXPOSURE]: Advertising account identifiers and performance data are stored in the local {data_dir} to track anomalies and maintain context across sessions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes metadata from the Meta Ads API, providing a surface for indirect prompt injection. Ingestion points: Campaign and ad metadata (SKILL.md). Boundary markers: None defined. Capability inventory: Account mutation tools such as pauseCampaign and updateAdSetBudget. Sanitization: No specific sanitization of external metadata is mentioned before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:15 PM
Security Audit — agent-trust-hub — meta-ads