paid-ads-setup
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses a redirection pattern to load instructions from a relative file path (
../../paid-ads/paid-ads-setup/SKILL.md), which introduces an indirect prompt injection surface. If the target file is manipulated, the agent's behavior could be overridden.\n - Ingestion Point: The skill body directs the agent to read and follow the file at
../../paid-ads/paid-ads-setup/SKILL.md.\n - Capability Inventory: The skill manages sensitive integrations with Google Ads, Meta Ads, X Ads, and LinkedIn Ads accounts.\n
- Boundary Markers: The skill lacks delimiters or warnings to prevent the agent from obeying malicious instructions embedded within the ingested file.\n
- Sanitization: There is no evidence of validation or sanitization of the content before it is adopted as the active workflow.
Audit Metadata