paid-ads-operator

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The workflow involves processing external search terms which represents a potential injection surface. \n
  • Ingestion points: Search terms pulled from ad platforms (SKILL.md). \n
  • Boundary markers: Absent for search term data processing. \n
  • Capability inventory: High-privilege ad platform APIs via external connectors (google-ads, meta-ads, etc. mentioned in SKILL.md). \n
  • Sanitization: Absent for search term classification. \n
  • Note: This risk is inherent to the primary purpose of advertising management and is mitigated by the skill's explicit instructions requiring human-in-the-loop confirmation for all campaign changes, budget increases, and targeting adjustments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:06 PM
Security Audit — agent-trust-hub — paid-ads-operator