product-ad-shot-design

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references several external domains in references/cases.md for visual reference and evidence gathering, including goodcase.ai, youmind.com, pbs.twimg.com, and x.com. These links are used to provide the agent with examples of finished media (MP4s and JPEGs) and original source context from social media. These references are integral to the skill's stated purpose of 'Product ad shot design'.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data by reading references/cases.md and inspecting linked media.
  • Ingestion points: The agent is instructed to read local evidence files and visit external URLs for media inspection.
  • Boundary markers: The workflow mandates selecting exactly one anchor case and naming it, which acts as a logical boundary. The instructions also specify a 'Preserve / Replace / Avoid' contract to separate case traits from user requirements.
  • Capability inventory: The agent uses image, video, or browser tools to inspect external content.
  • Sanitization: The skill includes explicit instructions not to invent original prompts or impersonate creators, focusing instead on transferring decision logic.
  • [DATA_EXFILTRATION]: The skill contains a strong safety directive in SKILL.md prohibiting the publishing, purchasing, or uploading of private assets without explicit user approval, which mitigates risks associated with data handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 05:35 AM
Security Audit — agent-trust-hub — product-ad-shot-design