skills/ai-vita/skills/ad-creative/Gen Agent Trust Hub

ad-creative

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted performance data and product marketing context files. This creates a surface for indirect prompt injection (Category 8) where malicious instructions could be embedded in the ingested data. This is documented as a necessary feature for creative iteration and is assessed as low risk.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for cloning external repositories from GitHub (e.g., jamiepine/voicebox) and installing packages via npm (e.g., remotion, create-video). These resources originate from well-known open-source projects or trusted vendors and are required for the skill's functionality.
  • [DATA_EXFILTRATION]: The skill facilitates network communication with several well-known third-party AI services including Google Gemini, OpenAI, and ElevenLabs. These operations are intended for content generation and do not access or transmit sensitive local configuration files or credentials.
  • [COMMAND_EXECUTION]: The skill references internal CLI tools for retrieving advertising performance data and provides example shell commands for rendering video assets and interacting with APIs. These commands are legitimate and within the expected scope of a performance marketing tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 05:17 AM
Security Audit — agent-trust-hub — ad-creative