educational-ad
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection due to its core function of processing and acting upon external, untrusted content.\n
- Ingestion points: User-provided offer facts, brand briefs, rough concepts, and existing advertisements ingested for review via the $video-analysis tool (SKILL.md).\n
- Boundary markers: The instructions do not define clear delimiters or explicitly instruct the agent to ignore directives that might be embedded within the source materials being analyzed.\n
- Capability inventory: The skill includes instructions to pass processed data to $image-batch-runner and $video-batch-runner for automated media production, which could be leveraged if the input data contains malicious instructions (references/workflow-handoff.md).\n
- Sanitization: While the skill enforces "Non-Imitation Boundaries," it lacks mechanisms to sanitize or validate input data against structural prompt injections.
Audit Metadata