ad-copy
Pass
Audited by Gen Agent Trust Hub on May 4, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes the
$ARGUMENTSvariable to interpolate user-provided input into the generative prompt. While it lacks explicit boundary markers (like XML tags or block delimiters) to isolate this untrusted data, the skill has no dangerous capabilities (e.g., network access, file writing, or command execution) that could be exploited via injection. The risk is limited to manipulating the text generation output. - [DATA_EXPOSURE]: The workflow involves reading local configuration and brand files such as
ad-copy/meta.json,core/global-constraints.json, andbrand-voice.md. These are standard practice for maintaining brand consistency and platform compliance and do not involve sensitive system credentials or private user data.
Audit Metadata