executive-reporting

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and summarize data from external advertising platforms, creating an indirect prompt injection vulnerability surface.\n
  • Ingestion points: Data from Google Ads (GAQL), Meta Marketing API, and LinkedIn Reporting API, specifically targeting campaign metadata and search terms (Workflow 1, Step 1).\n
  • Boundary markers: There are no explicit delimiters or instructions provided to separate external data from agent instructions, which could allow instructions embedded in ad data to influence agent behavior.\n
  • Capability inventory: The agent uses this data to generate natural language narrative insights and report summaries.\n
  • Sanitization: The workflow does not include any steps to sanitize, filter, or validate the content of the strings retrieved from the external platforms.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 04:03 AM
Security Audit — agent-trust-hub — executive-reporting