ad-creative

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands using node, curl, npx, and ffmpeg to retrieve ad performance metrics and render video creative.
  • [EXTERNAL_DOWNLOADS]: Fetches assets and references configuration from well-known AI service providers including Google Gemini, OpenAI, ElevenLabs, and Replicate. It also references the open-source Voicebox project for local audio generation.
  • [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection via the processing of untrusted external content. 1. Ingestion points: Ingests marketing context from local files (.agents/product-marketing-context.md) and ad performance data from platform-specific API outputs or manual pastes. 2. Boundary markers: Lacks explicit delimiters or instructions to prevent the agent from obeying commands embedded within the processed context or data. 3. Capability inventory: The agent has access to shell command execution (node, npx), file system access, and network operations. 4. Sanitization: There is no evidence of input validation or sanitization before external data is used in prompts or processing pipelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 12:25 AM
Security Audit — agent-trust-hub — ad-creative