ad-creative
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands using
node,curl,npx, andffmpegto retrieve ad performance metrics and render video creative. - [EXTERNAL_DOWNLOADS]: Fetches assets and references configuration from well-known AI service providers including Google Gemini, OpenAI, ElevenLabs, and Replicate. It also references the open-source Voicebox project for local audio generation.
- [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection via the processing of untrusted external content. 1. Ingestion points: Ingests marketing context from local files (
.agents/product-marketing-context.md) and ad performance data from platform-specific API outputs or manual pastes. 2. Boundary markers: Lacks explicit delimiters or instructions to prevent the agent from obeying commands embedded within the processed context or data. 3. Capability inventory: The agent has access to shell command execution (node,npx), file system access, and network operations. 4. Sanitization: There is no evidence of input validation or sanitization before external data is used in prompts or processing pipelines.
Audit Metadata