competitive-ads-extractor

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists entirely of markdown documentation. It does not include any executable scripts, source code, or binary files that would run on the agent's host system.
  • [DATA_EXFILTRATION]: The instructions direct the agent to save extracted data and analysis to local file paths within the user's home directory (e.g., ~/competitor-ads/). There are no commands or instructions to transmit this data to external or unauthorized servers.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because its core function involves ingesting untrusted text from external web pages (competitor ad libraries) and analyzing it.
  • Ingestion points: Public ad copy and metadata from the Facebook Ad Library and LinkedIn.
  • Boundary markers: Absent; the instructions do not provide delimiters or warnings for the agent to treat scraped content as untrusted data separate from its instructions.
  • Capability inventory: The agent performs file system write operations (saving screenshots and reports) and conducts natural language analysis on the scraped data.
  • Sanitization: No mechanisms for sanitizing or escaping the external content before processing are included.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 04:24 PM
Security Audit — agent-trust-hub — competitive-ads-extractor