tiktok-creative-strategy

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it is designed to ingest and process external content from app store metadata and local context files.
  • Ingestion points: The skill reads app-ads-context.md and utilizes the get_app and get_app_screenshots tools to retrieve external application information.
  • Boundary markers: There are no explicit boundary markers or instructions provided to the agent to disregard potential malicious directives embedded within the external app data or screenshots.
  • Capability inventory: The skill includes tools to list advertisement identities (tiktok_ads_list_identities) and provides strategies for managing Spark Ad batches.
  • Sanitization: The instructions do not define sanitization or validation logic for data retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 10:19 PM
Security Audit — agent-trust-hub — tiktok-creative-strategy