paid-ads
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest context from external project files to tailor its advertising strategy recommendations. While this is standard behavior, it creates a surface for indirect instructions if those files are modified by untrusted sources.
- Ingestion points: Reads
.agents/product-marketing-context.md,.claude/product-marketing-context.md, and multiple files in thereferences/directory. - Boundary markers: No specific boundary markers or instructions to ignore embedded commands are present in the skill for these files.
- Capability inventory: The skill references potential access to advertising platform tools (Google Ads, Meta, LinkedIn) via MCP integrations documented in
../../tools/integrations/. - Sanitization: No validation or sanitization logic is specified for the content retrieved from the marketing context files.
Audit Metadata