skills/novoads/agent-skills/pixar-ad/Gen Agent Trust Hub

pixar-ad

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted product data from external URLs and listing text (Gate 1) to generate visual prompts and audio scripts. While no boundary markers are explicitly used to isolate this data, the workflow requires mandatory human verification at the 'Board Gate' (Gate 3) and 'Caption Gate' (Gate 8) before high-cost generation or final assembly. Capability inventory includes curl for API interaction, ffmpeg/ffprobe for video processing, and local Python scripts.
  • [COMMAND_EXECUTION]: The skill constructs and executes shell commands for ffmpeg, ffprobe, and curl by interpolating parameters such as job IDs, file paths, and durations derived from API responses. This is a primary function of the skill used for asset management and video assembly.
  • [EXTERNAL_DOWNLOADS]: The skill downloads generated video and audio media from the official Novoads API (api.novoads.ai) using curl. These downloads are part of the core operational flow and target the vendor's own infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:34 AM
Security Audit — agent-trust-hub — pixar-ad