ads-budget
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies business context by ingesting untrusted data from user-provided URLs or session history, which is then reflected in a generated local file.
- Ingestion points: Step 2 of the Execution Flow in
SKILL.mdindicates the agent should use context from previously provided URLs or session commands like/ads strategy. - Boundary markers: Absent; the instructions lack delimiters or specific guardrail prompts to ensure the agent ignores potentially malicious instructions embedded within the ingested URL content.
- Capability inventory: The skill possesses file-write capabilities, specifically creating and writing to
ADS-BUDGET.md(Rule 12). - Sanitization: Absent; there is no mention of sanitizing, escaping, or validating the content retrieved from external business contexts before it is processed.
Audit Metadata