ad-creative-intelligence

Warn

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The workflow executes shell commands using the orth tool where user-supplied input (<competitor_name>) is interpolated directly into a URL string. This creates a risk of command injection if the input is not properly sanitized, potentially allowing an attacker to execute arbitrary commands by including shell metacharacters in the competitor name.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it scrapes data from external advertising platforms and passes it to the LLM for analysis without sanitization or boundary markers. 1. Ingestion points: Scraped content from Meta and Google ads libraries. 2. Boundary markers: Absent. 3. Capability inventory: Shell command execution via orth. 4. Sanitization: Only a basic length check is performed on the scraped content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 19, 2026, 02:47 AM
Security Audit — agent-trust-hub — ad-creative-intelligence