paid-ads
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: All instructional content and reference files are consistent with the skill's stated purpose of assisting with paid media management. The logic for budget allocation, bidding strategies, and performance monitoring follows standard advertising guidelines.\n- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it is instructed to process data from an external file (
.claude/product-marketing-context.md) which could contain untrusted instructions if modified by a third party.\n - Ingestion points: Reads marketing context from the
.claude/product-marketing-context.mdfile (SKILL.md).\n - Boundary markers: Absent; there are no specified delimiters or instructions to ignore embedded prompts within the context file.\n
- Capability inventory: The skill is designed to interact with and manage advertising platform accounts through integrated tools (e.g., Google Ads MCP).\n
- Sanitization: Absent; no validation or sanitization of the context file content is performed before processing.
Audit Metadata