tiktok-creative-strategy
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it is designed to ingest and process external content from app store metadata and local context files.
- Ingestion points: The skill reads
app-ads-context.mdand utilizes theget_appandget_app_screenshotstools to retrieve external application information. - Boundary markers: There are no explicit boundary markers or instructions provided to the agent to disregard potential malicious directives embedded within the external app data or screenshots.
- Capability inventory: The skill includes tools to list advertisement identities (
tiktok_ads_list_identities) and provides strategies for managing Spark Ad batches. - Sanitization: The instructions do not define sanitization or validation logic for data retrieved from external sources before it is processed by the agent.
Audit Metadata