educational-ad
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-supplied data, including brand briefs, offer facts, and existing ad media (via the
$media-analysistool). This content is used to generate detailed production scripts that are passed to downstream media generation agents, creating an attack surface where malicious instructions in a brief could influence the output of production tools. - Ingestion points: User-supplied 'offer, brand brief, rough concept, or approved facts' in the Create Workflow, and external ad media in the Review Workflow (SKILL.md).
- Boundary markers: The skill uses a strict 'Educational Grammar Plan' and 'Shot Script Rubric' to constrain output. It also includes instructions to 'Stop before production until the user approves.'
- Capability inventory: The skill invokes the
$image-batch-runnerand$video-batch-runnertools for media production based on generated scripts (references/workflow-handoff.md). - Sanitization: The skill implements a 'Claim Discipline' system (references/educational-grammar.md) and a 'Causal Closure Gate' (references/shot-script-rubric.md) to validate that all generated claims are supported by approved facts before proceeding.
Audit Metadata