ads-budget

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies business context by ingesting untrusted data from user-provided URLs or session history, which is then reflected in a generated local file.
  • Ingestion points: Step 2 of the Execution Flow in SKILL.md indicates the agent should use context from previously provided URLs or session commands like /ads strategy.
  • Boundary markers: Absent; the instructions lack delimiters or specific guardrail prompts to ensure the agent ignores potentially malicious instructions embedded within the ingested URL content.
  • Capability inventory: The skill possesses file-write capabilities, specifically creating and writing to ADS-BUDGET.md (Rule 12).
  • Sanitization: Absent; there is no mention of sanitizing, escaping, or validating the content retrieved from external business contexts before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:50 PM
Security Audit — agent-trust-hub — ads-budget