ad-copy-variants

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data, creating a surface for indirect prompt injection.
  • Ingestion points: The agent collects customer reviews, testimonials, sales-call notes, and destination page content through the 'Interview' process in SKILL.md.
  • Boundary markers: The skill instructions do not specify the use of unique delimiters or boundary markers to isolate this untrusted data from the system's operational instructions.
  • Capability inventory: The skill primarily performs text generation tasks and suggests web browsing for verifying platform specifications.
  • Sanitization: The skill contains a 'Grounding Rule' in SKILL.md that forbids the creation of fabricated claims and requires all proof points to be traceable to user-supplied evidence, acting as a validation step for external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:32 PM
Security Audit — agent-trust-hub — ad-copy-variants