paid-media
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of instructional templates and guidelines for digital marketing. No malicious behavior or security risks were identified.
- [PROMPT_INJECTION]: No attempts to override system prompts, bypass safety filters, or extract sensitive instructions were found in any of the skill files.
- [DATA_EXFILTRATION]: No hardcoded credentials, sensitive environment variables, or unauthorized network exfiltration patterns were detected. References to marketing providers (e.g., Google Ads, Meta) are for legitimate instructional purposes.
- [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote scripts. The JavaScript files in the
tests/directory are local validation utilities that perform basic file existence checks and do not interact with the network or external dependencies. - [COMMAND_EXECUTION]: There are no high-risk command execution patterns, privilege escalation attempts (sudo), or persistence mechanisms (cron jobs) found in the skill package.
- [OBFUSCATION]: No obfuscated content, hidden Unicode characters, or encoded strings (such as Base64-encoded commands) were discovered during the analysis.
- [INDIRECT_PROMPT_INJECTION]: While the skill defines ingestion points for external marketing data (objectives, budgets, landing pages), it does not possess high-risk capabilities that would allow this data to trigger dangerous system operations. The risk is considered negligible.
Audit Metadata