ad-creative
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data in the form of performance metrics (CSV, paste, or API output) to iterate on ad copy.
- Ingestion points: Performance data provided by the user in
SKILL.md(Mode 2: Iterate from Performance Data). - Boundary markers: Absent; there are no specific instructions to the agent to treat this data as untrusted or to use delimiters.
- Capability inventory: The agent can write files, execute local CLI tools, and make network requests to various AI service APIs.
- Sanitization: Not present; the data is directly analyzed to identify winning patterns and generate new content.
- [REMOTE_CODE_EXECUTION]: The skill encourages the generation and execution of dynamic code. In
references/generative-tools.md, it suggests using AI to design React templates for the Remotion framework, which are subsequently rendered into video files. - [COMMAND_EXECUTION]: The skill provides instructions and examples for executing shell commands and local scripts, such as
node tools/clis/google-ads.jsfor data retrieval andnpx remotion renderfor video production. - [EXTERNAL_DOWNLOADS]: The skill references external resources and APIs. It includes instructions to clone the Voicebox repository from GitHub (
jamiepine/voicebox) and providescurlexamples for interacting with official APIs from Google (Gemini) and ElevenLabs. These are well-known services used for their primary intended purpose.
Audit Metadata