ads-linkedin
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill's primary function is to process external LinkedIn Ads data and Campaign Manager exports, which presents an attack surface for indirect prompt injection.
- Ingestion points: The 'Process' section in
SKILL.mdspecifies collecting LinkedIn Ads data and Campaign Manager exports. - Boundary markers: There are no specified delimiters or instructions to ignore embedded prompts within the external data.
- Capability inventory: The skill performs read-only operations on local reference files (e.g.,
ads/references/linkedin-audit.md) and logical data evaluation; it does not exhibit dangerous capabilities like code execution or network exfiltration. - Sanitization: No sanitization or validation of the ingested CSV or export data is defined in the instructions.
Audit Metadata