adcp-media-buy

Pass

Audited by Gen Agent Trust Hub on Mar 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious code, obfuscation, or unauthorized data access patterns were detected. The skill instructions and schemas focus on standard advertising protocol operations.- [PROMPT_INJECTION]: The get_products tool processes natural language briefs, creating a surface for indirect prompt injection where untrusted data could attempt to influence the agent's product selection. This is a standard feature for the protocol's discovery function. (1) Ingestion point: The brief property in schemas/get-products-request.json. (2) Boundary markers: No delimiters or specific instructions to ignore embedded commands are present in the schema. (3) Capability inventory: Tools for campaign creation (create_media_buy), updating (update_media_buy), and asset synchronization (sync_creatives) described in SKILL.md. (4) Sanitization: No explicit sanitization or validation logic for the brief content is defined in the provided schema.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 1, 2026, 06:30 AM