creating-campaigns-ads-audiences

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute local Python scripts (create_custom_audience.py, create_campaign.py, update_campaign.py) to automate the creation and management of Meta advertising assets. These commands are integral to the skill's stated purpose and do not involve remote code downloads.
  • [PROMPT_INJECTION]: The skill contains explicit safety guidelines to prevent accidental actions, notably the requirement that all campaigns, ad sets, and ads must be created in a PAUSED state and only activated upon user confirmation. It also mandates that ad copy be used exactly as provided by the user, reducing the risk of the agent generating unauthorized or deceptive content.
  • [DATA_EXFILTRATION]: While the skill interacts with Meta's API endpoints (e.g., /{account_id}/adsets), these operations are limited to the intended advertising management functions. No evidence was found of sensitive local data (such as credentials or environment files) being transmitted to unauthorized external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 09:08 AM
Security Audit — agent-trust-hub — creating-campaigns-ads-audiences