manage-campaign

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOWPROMPT_INJECTIONNO_CODE
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill defines a surface for retrieving and managing untrusted data (research reports, ad copy, and parameters). This content could contain malicious instructions designed to influence the agent's workflow transitions.\n
  • Ingestion points: The research, ad_copy, and parameters fields retrieved from the campaign database.\n
  • Boundary markers: Absent. The output format uses a flat JSON structure without explicit delimiters or instructions to ignore embedded commands.\n
  • Capability inventory: This skill provides workflow logic and state reporting; it does not possess side-effect capabilities like file writing or command execution.\n
  • Sanitization: No sanitization or validation of the text content within the campaign fields is described.\n- [No Code] (INFO): The provided skill consists entirely of markdown instructions and data schemas. No executable scripts, binaries, or shell commands were found in the file.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 08:51 AM