ad-creative
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides examples of using
curlto interact with external APIs such as Google's Gemini and ElevenLabs. It also suggests cloning the Voicebox repository from GitHub. These are presented as legitimate resources for generating ad visuals and audio assets. - [COMMAND_EXECUTION]: Instructions contain shell command examples for executing local Node.js scripts to fetch advertising reports, using
ffmpegfor media processing, and employingnpxfor project initialization. - [DYNAMIC_EXECUTION]: The skill references the Remotion framework, which generates video by executing React and TypeScript code at runtime to create deterministic, data-driven visuals based on templates.
- [INDIRECT_PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection by processing external performance metrics provided by users or APIs. * Ingestion points: Performance data ingested via CSV, text pastes, or API responses in the performance iteration workflow (SKILL.md). * Boundary markers: The instructions do not define specific delimiters or warnings to ignore instructions embedded within the ingested data. * Capability inventory: Includes capabilities for network access via ad platform tools and local command execution for media processing. * Sanitization: There is no mention of sanitizing or validating the ingested performance data before using it to influence ad copy generation.
Audit Metadata