ad-genius

Pass

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its research protocol, which harvests verbatim audience quotes and tension points from public platforms like Reddit and App Store reviews.
  • Ingestion points: The file pipeline/research.md (Step 1: Audience deep-dive) specifies collecting verbatim quotes from third-party social media and review platforms to inform ad copy.
  • Boundary markers: The instructions do not explicitly define delimiters or instructions to isolate these external quotes from the agent's core instruction set during script generation.
  • Capability inventory: The agent has full file-system read/write access for managing project directories, generated scripts, and editorial scorecards as defined in SKILL.md and pipeline/edit.md.
  • Sanitization: The risk is mitigated by a mandatory three-pass quality gate in pipeline/edit.md, which includes a 'Stop-Slop Scan' and a 6-dimension scorecard to ensure output aligns with brand voice and safety policies.
Audit Metadata
Risk Level
SAFE
Analyzed
May 5, 2026, 10:43 AM
Security Audit — agent-trust-hub — ad-genius