paid-ads-operator
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The workflow involves processing external search terms which represents a potential injection surface. \n
- Ingestion points: Search terms pulled from ad platforms (SKILL.md). \n
- Boundary markers: Absent for search term data processing. \n
- Capability inventory: High-privilege ad platform APIs via external connectors (google-ads, meta-ads, etc. mentioned in SKILL.md). \n
- Sanitization: Absent for search term classification. \n
- Note: This risk is inherent to the primary purpose of advertising management and is mitigated by the skill's explicit instructions requiring human-in-the-loop confirmation for all campaign changes, budget increases, and targeting adjustments.
Audit Metadata