microsoft-ads
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze search term reports and account data, which are external, untrusted sources. An attacker could potentially craft search queries that, when appearing in an audit report, attempt to influence the agent's instructions or strategy recommendations.
- Ingestion points: Search term reports (referenced in EXAMPLES.md and REFERENCE.md) and campaign metadata.
- Boundary markers: None identified; the instructions do not define specific delimiters or instructions to ignore embedded prompts in processed data.
- Capability inventory: Mentions the Bing Ads API for account management, including operations to add or update campaigns, keywords, and ads (REFERENCE.md).
- Sanitization: None identified; the skill does not specify methods for filtering or escaping content from search queries before processing.
Audit Metadata