creative

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a creative production system that utilizes standard generative AI APIs for marketing tasks. No malicious patterns or behaviors were identified.
  • [SAFE]: The skill correctly instructs the use of environment variables (e.g., os.environ["GEMINI_API_KEY"]) for managing API secrets, following secure development best practices for secret management.
  • [EXTERNAL_DOWNLOADS]: The skill references external generative AI services and models, including Google Gemini, OpenAI Sora, Kling AI, and ElevenLabs. These are established technology services and are considered safe references in the context of this skill's functionality.
  • [PROMPT_INJECTION]: The skill ingests data from brand configuration files (brand/voice-profile.md, brand/creative-kit.md, brand/positioning.md) to guide asset generation. This creates a potential surface for indirect prompt injection; however, the risk is assessed as low given the local file context and the skill's specific purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 02:06 PM
Security Audit — agent-trust-hub — creative