paid-media

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional templates and guidelines for digital marketing. No malicious behavior or security risks were identified.
  • [PROMPT_INJECTION]: No attempts to override system prompts, bypass safety filters, or extract sensitive instructions were found in any of the skill files.
  • [DATA_EXFILTRATION]: No hardcoded credentials, sensitive environment variables, or unauthorized network exfiltration patterns were detected. References to marketing providers (e.g., Google Ads, Meta) are for legitimate instructional purposes.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote scripts. The JavaScript files in the tests/ directory are local validation utilities that perform basic file existence checks and do not interact with the network or external dependencies.
  • [COMMAND_EXECUTION]: There are no high-risk command execution patterns, privilege escalation attempts (sudo), or persistence mechanisms (cron jobs) found in the skill package.
  • [OBFUSCATION]: No obfuscated content, hidden Unicode characters, or encoded strings (such as Base64-encoded commands) were discovered during the analysis.
  • [INDIRECT_PROMPT_INJECTION]: While the skill defines ingestion points for external marketing data (objectives, budgets, landing pages), it does not possess high-risk capabilities that would allow this data to trigger dangerous system operations. The risk is considered negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:32 PM