paid-ads-amazon

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to read and follow instructions from an external relative file path (../../paid-ads/paid-ads-amazon/SKILL.md). This establishes an indirect prompt injection surface where the agent's behavior is governed by content outside the current skill definition. * Ingestion points: Relative path file read in SKILL.md. * Boundary markers: None provided to delimit the external content. * Capability inventory: Inherits all capabilities and tool access defined in the target file. * Sanitization: No validation or sanitization is performed on the ingested instructions.
  • [NO_CODE]: No executable scripts (Python, Node.js, Shell) were found in the skill package, reducing the risk of direct malicious code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:15 PM
Security Audit — agent-trust-hub — paid-ads-amazon