ad-creative

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data in the form of performance metrics (CSV, paste, or API output) to iterate on ad copy.
  • Ingestion points: Performance data provided by the user in SKILL.md (Mode 2: Iterate from Performance Data).
  • Boundary markers: Absent; there are no specific instructions to the agent to treat this data as untrusted or to use delimiters.
  • Capability inventory: The agent can write files, execute local CLI tools, and make network requests to various AI service APIs.
  • Sanitization: Not present; the data is directly analyzed to identify winning patterns and generate new content.
  • [REMOTE_CODE_EXECUTION]: The skill encourages the generation and execution of dynamic code. In references/generative-tools.md, it suggests using AI to design React templates for the Remotion framework, which are subsequently rendered into video files.
  • [COMMAND_EXECUTION]: The skill provides instructions and examples for executing shell commands and local scripts, such as node tools/clis/google-ads.js for data retrieval and npx remotion render for video production.
  • [EXTERNAL_DOWNLOADS]: The skill references external resources and APIs. It includes instructions to clone the Voicebox repository from GitHub (jamiepine/voicebox) and provides curl examples for interacting with official APIs from Google (Gemini) and ElevenLabs. These are well-known services used for their primary intended purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:56 PM
Security Audit — agent-trust-hub — ad-creative