paid-ads

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest context from external project files to tailor its advertising strategy recommendations. While this is standard behavior, it creates a surface for indirect instructions if those files are modified by untrusted sources.
  • Ingestion points: Reads .agents/product-marketing-context.md, .claude/product-marketing-context.md, and multiple files in the references/ directory.
  • Boundary markers: No specific boundary markers or instructions to ignore embedded commands are present in the skill for these files.
  • Capability inventory: The skill references potential access to advertising platform tools (Google Ads, Meta, LinkedIn) via MCP integrations documented in ../../tools/integrations/.
  • Sanitization: No validation or sanitization logic is specified for the content retrieved from the marketing context files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 02:59 PM
Security Audit — agent-trust-hub — paid-ads