meta-ads-audit
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and interpret untrusted data from external sources, which creates a potential surface for indirect prompt injection (SKILL.md).
- Ingestion points: Data enters the agent's context through CSV exports, screenshots, pasted tables, and output from Model Context Protocol (MCP) tools.
- Boundary markers: The skill does not explicitly define delimiters or boundary markers to separate user-provided data from the analytical instructions.
- Capability inventory: The skill possesses no capabilities for file writing, shell command execution, or network exfiltration. It is explicitly limited to generating text-based recommendations for the user to implement manually.
- Sanitization: No input sanitization or filtering mechanisms are specified.
- [SAFE]: The skill implements extensive 'Universal Guardrails' that mitigate common risks in automated ad management, such as prohibiting unauthorized budget reallocations and preventing the pausing of top-performing ads. It also includes mandatory health checks and data source verification steps to ensure the accuracy and reliability of the analysis.
Audit Metadata