educational-ad

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-supplied data, including brand briefs, offer facts, and existing ad media (via the $media-analysis tool). This content is used to generate detailed production scripts that are passed to downstream media generation agents, creating an attack surface where malicious instructions in a brief could influence the output of production tools.
  • Ingestion points: User-supplied 'offer, brand brief, rough concept, or approved facts' in the Create Workflow, and external ad media in the Review Workflow (SKILL.md).
  • Boundary markers: The skill uses a strict 'Educational Grammar Plan' and 'Shot Script Rubric' to constrain output. It also includes instructions to 'Stop before production until the user approves.'
  • Capability inventory: The skill invokes the $image-batch-runner and $video-batch-runner tools for media production based on generated scripts (references/workflow-handoff.md).
  • Sanitization: The skill implements a 'Claim Discipline' system (references/educational-grammar.md) and a 'Causal Closure Gate' (references/shot-script-rubric.md) to validate that all generated claims are supported by approved facts before proceeding.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 02:16 AM
Security Audit — agent-trust-hub — educational-ad