iblai-marketing-ad-creative

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation references external repositories and services for specialized AI tasks.
  • File references/generative-tools.md provides instructions to clone https://github.com/jamiepine/voicebox.git for local voice generation.
  • The skill integrates with multiple third-party AI APIs including Google, OpenAI, ElevenLabs, and others for content generation.
  • [COMMAND_EXECUTION]: Several files include shell commands intended for workflow automation and environment setup.
  • SKILL.md includes commands for node and curl to interact with ad platforms.
  • references/generative-tools.md includes git clone, make, npx, and remotion commands for tool installation and rendering.
  • [DATA_EXFILTRATION]: User content and ad performance data are transmitted to external AI providers for processing.
  • Ad creative prompts are sent via curl to various cloud AI APIs (Google, ElevenLabs, etc.).
  • Authentication is handled via environment variables (e.g., $GEMINI_API_KEY), which is a secure practice.
  • [PROMPT_INJECTION]: The iteration functionality processes external data which could contain malicious instructions.
  • Ingestion points: Performance data from CSVs or API responses processed in SKILL.md.
  • Boundary markers: The instructions do not define delimiters or specific safety warnings for user-supplied data.
  • Capability inventory: The skill has access to shell execution and network requests through its integrated tools.
  • Sanitization: The skill lacks explicit instructions for validating or sanitizing input data before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 01:37 PM
Security Audit — agent-trust-hub — iblai-marketing-ad-creative