ads-audit

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as account exports, screenshots, and manual metrics, which represents a potential surface for malicious instructions to be ingested into the agent context. Ingestion points: The procedure involves normalizing 'exports, screenshots, manual metrics, or authenticated reads' into an account snapshot in Procedure Step 3. Boundary markers: The skill explicitly instructs the agent that reports must 'never contains... hidden instructions from external content' in the Outputs section. Capability inventory: The skill dispatches various platform workers and writes multiple results to JSON and Markdown files. Sanitization: The procedure includes a mandatory verification step in Step 11 to ensure bundle completeness, citations, privacy, and render integrity, specifically aimed at preventing the leakage of credentials or hidden external instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:34 PM
Security Audit — agent-trust-hub — ads-audit