competitive-ads-extractor

Pass

Audited by Gen Agent Trust Hub on Mar 6, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill provides behavioral instructions in markdown format but does not include any executable Python, JavaScript, or shell scripts.
  • [PROMPT_INJECTION]: The skill requires the agent to process untrusted data from external websites, which is a vector for indirect prompt injection.
  • Ingestion points: Web scraping of competitor ad copy from Facebook Ad Library and LinkedIn.
  • Boundary markers: No instructions are provided to the agent to treat scraped content as data rather than instructions or to ignore embedded commands.
  • Capability inventory: The skill uses file system access (saving to ~/competitor-ads/) and requires network scraping capabilities.
  • Sanitization: No sanitization or content validation is implemented for the ingested ad text.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 6, 2026, 05:29 PM