ads-audit
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as account exports, screenshots, and manual metrics, which represents a potential surface for malicious instructions to be ingested into the agent context. Ingestion points: The procedure involves normalizing 'exports, screenshots, manual metrics, or authenticated reads' into an account snapshot in Procedure Step 3. Boundary markers: The skill explicitly instructs the agent that reports must 'never contains... hidden instructions from external content' in the Outputs section. Capability inventory: The skill dispatches various platform workers and writes multiple results to JSON and Markdown files. Sanitization: The procedure includes a mandatory verification step in Step 11 to ensure bundle completeness, citations, privacy, and render integrity, specifically aimed at preventing the leakage of credentials or hidden external instructions.
Audit Metadata