conversational-ads

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to provide guidance and local linting tools for conversational advertising. A thorough review of the provided scripts and markdown files reveals no malicious intent or security risks.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were found. The scripts scripts/conversational_ad_planner.py and scripts/answer_adjacent_copy_linter.py rely entirely on Python's standard library and do not invoke external compilers, package managers, or remote shells.
  • [DATA_EXFILTRATION]: There are no network-capable operations (like curl, requests, or socket) present in the scripts. Data processing is confined to local JSON inputs and standard output.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests user-provided data (ad copy and marketing briefs), it does not have the capability to act on malicious instructions within that data.
  • Ingestion points: scripts/conversational_ad_planner.py (brief JSON) and scripts/answer_adjacent_copy_linter.py (ads JSON).
  • Boundary markers: Uses structured JSON for data ingestion.
  • Capability inventory: No subprocess calls, file-write operations, or network requests are present.
  • Sanitization: Not applicable as the scripts only produce text reports.
  • [CREDENTIALS_SAFE]: No hardcoded API keys, tokens, or private secrets were found. The skill correctly recommends using standard UTM parameters and platform macros for tracking.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 02:59 PM
Security Audit — agent-trust-hub — conversational-ads