educational-ad

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection due to its core function of processing and acting upon external, untrusted content.\n
  • Ingestion points: User-provided offer facts, brand briefs, rough concepts, and existing advertisements ingested for review via the $video-analysis tool (SKILL.md).\n
  • Boundary markers: The instructions do not define clear delimiters or explicitly instruct the agent to ignore directives that might be embedded within the source materials being analyzed.\n
  • Capability inventory: The skill includes instructions to pass processed data to $image-batch-runner and $video-batch-runner for automated media production, which could be leveraged if the input data contains malicious instructions (references/workflow-handoff.md).\n
  • Sanitization: While the skill enforces "Non-Imitation Boundaries," it lacks mechanisms to sanitize or validate input data against structural prompt injections.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 09:30 AM
Security Audit — agent-trust-hub — educational-ad