paid-ads
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill is entirely composed of informational markdown files that provide marketing strategy, best practices, and campaign setup checklists. It does not contain executable scripts, shell commands, or network-active code.- [INDIRECT_PROMPT_INJECTION]: The skill outlines a process for ingesting external data that could serve as a surface for indirect prompt injection, though no exploitable code is present to act on this data.\n
- Ingestion points: The skill instructs the agent to gather landing page URLs and product marketing context from the user or from .agents/product-marketing-context.md.\n
- Boundary markers: No explicit instructions are provided to the agent to treat this ingested content as untrusted or to ignore embedded instructions.\n
- Capability inventory: The skill provides instructions for utilizing ad platform tool integrations (Google Ads, Meta, LinkedIn) for campaign management but includes no shell, file-write, or network capabilities within the skill's own files.\n
- Sanitization: No validation or sanitization routines are defined for the landing page URLs or product context gathered at runtime.
Audit Metadata