ad-creative

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely self-contained and focused on marketing copy generation. Analysis of all components, including the Python validation script, revealed no security risks.
  • [COMMAND_EXECUTION]: The skill utilizes scripts/ad_copy_validator.py to check ad copy against platform specifications. This script is safe as it relies solely on the Python standard library (json, re, sys) and does not perform network operations, file system modifications, or arbitrary code execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied product descriptions and performance data. While this is an ingestion point for external data, the skill lacks high-privilege capabilities (such as network exfiltration or shell access) that would make such an injection high-risk. The processing is limited to text generation and local validation.
  • [DATA_EXPOSURE]: The skill requests ad performance data (CTR, CVR, CPA) to assist in iteration. This data is used exclusively within the session context for the stated purpose of creative optimization and is not transmitted to external servers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:40 PM
Security Audit — agent-trust-hub — ad-creative