google-ads-scripts
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- [Indirect Prompt Injection] (SAFE): The skill templates ingest campaign and keyword data from the Google Ads API and structured data from Google Sheets. This ingestion is essential for the skill's primary purpose of automation. No significant vulnerability was identified as the data sources are typically internal to the user's environment.\n- [Data Exposure & Exfiltration] (SAFE): No sensitive data is transmitted to unauthorized domains. Logging and notification functions use standard Google Workspace services (SpreadsheetApp, MailApp) and target the user's own account.\n- [Hardcoded Credentials] (SAFE): No hardcoded API keys or secrets were detected. The scripts use clear placeholders for configuration IDs (e.g., YOUR_SPREADSHEET_ID).
Audit Metadata