ad-creative

Pass

Audited by Gen Agent Trust Hub on Apr 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and provides documentation for using several third-party AI platforms for creative generation, including Google Gemini, OpenAI, ElevenLabs, Runway, and others.
  • [EXTERNAL_DOWNLOADS]: Provides instructions to clone the Voicebox open-source repository from GitHub (jamiepine/voicebox) for local voice cloning and audio production.
  • [COMMAND_EXECUTION]: Documents the use of CLI tools for ad platforms (e.g., google-ads, meta-ads) to retrieve performance insights and manage campaign assets.
  • [COMMAND_EXECUTION]: Includes example shell commands for rendering templated video variations using the Remotion framework and interacting with generative APIs via curl.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and process external ad performance data.
  • Ingestion points: Ad performance data provided via CSV, text paste, or API output (SKILL.md).
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are defined for the ingested data.
  • Capability inventory: The skill utilizes platform-specific CLI tools and makes outbound API requests to generative services.
  • Sanitization: No validation or sanitization mechanisms for the external performance data were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 26, 2026, 10:15 PM
Security Audit — agent-trust-hub — ad-creative