ads-strategy
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests raw text from external websites which is then interpolated into the system prompts of five specialized sub-agents.
- Ingestion points: External business intelligence is gathered via
WebFetchfor homepage content andWebSearchfor competitor reviews and industry data in Phase 1. - Boundary markers: The sub-agent prompts use a simple 'CONTEXT:' header but lack robust delimiters (such as XML tags or unique string sequences) and omit instructions to disregard potentially malicious commands embedded in the fetched data.
- Capability inventory: The skill utilizes
WebFetch,WebSearch, and theAgenttool to delegate tasks, and it has the capability to write the synthesized results to a local Markdown file. - Sanitization: There is no evidence of filtering or sanitizing the strings extracted from HTML elements (like meta tags, hero sections, and H1 tags) before they are provided to the sub-agents.
Audit Metadata