ads-funnel
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill fetches content from external, untrusted websites using the
WebFetchtool based on user-provided URLs. This creates a surface for indirect prompt injection where malicious instructions embedded in a target website could attempt to influence the agent's behavior. - Ingestion points: Website content fetched via
WebFetchinSKILL.md(Step 1 in Execution Flow). - Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore' warnings for the fetched content.
- Capability inventory: The skill is designed to write output to a file named
ADS-FUNNEL.md. It does not explicitly manifest high-risk capabilities like shell execution or network POST requests in the provided file. - Sanitization: Absent. There is no mention of filtering or sanitizing the retrieved website data before processing.
Audit Metadata