ad-yield-optimization

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and analyze untrusted data from the target codebase, including configuration files and compliance declarations. \n
  • Ingestion points: Steps 1.1 and 1.4 involve scanning the codebase for ad stack components and compliance files like ads.txt and sellers.json. \n
  • Boundary markers: The instructions lack explicit boundary markers or delimiters to isolate untrusted content from the system prompt. \n
  • Capability inventory: The agent has capabilities to read arbitrary files from the codebase and write analysis reports to the filesystem (e.g., docs/ad-yield-optimization-analysis.md). \n
  • Sanitization: There is no evidence of content sanitization or instruction-filtering for the data being analyzed.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:56 AM
Security Audit — agent-trust-hub — ad-yield-optimization