ad-creative-fatigue
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as a diagnostic framework and does not include any code, shell commands, or network operations. All external references are directed toward other skills within the author's own workspace ('mbfinotti'), representing normal modular functionality rather than a supply chain risk. No evidence of prompt injection, obfuscation, or unauthorized data access was found.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface which is inherently susceptible to indirect prompt injection, although the risk is minimized by the lack of dangerous capabilities.
- Ingestion points: The skill ingests untrusted data through user-supplied performance exports and answers to interview questions defined in the workflow.
- Boundary markers: No specific delimiters or boundary markers are defined to isolate untrusted data from the agent's instructions.
- Capability inventory: The skill is limited to text analysis and advice generation. It has no access to the file system, network, or subprocess execution environments.
- Sanitization: The skill does not implement specific sanitization or validation routines for the ingested data.
Audit Metadata