ad-genius
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its research protocol, which harvests verbatim audience quotes and tension points from public platforms like Reddit and App Store reviews.
- Ingestion points: The file
pipeline/research.md(Step 1: Audience deep-dive) specifies collecting verbatim quotes from third-party social media and review platforms to inform ad copy. - Boundary markers: The instructions do not explicitly define delimiters or instructions to isolate these external quotes from the agent's core instruction set during script generation.
- Capability inventory: The agent has full file-system read/write access for managing project directories, generated scripts, and editorial scorecards as defined in
SKILL.mdandpipeline/edit.md. - Sanitization: The risk is mitigated by a mandatory three-pass quality gate in
pipeline/edit.md, which includes a 'Stop-Slop Scan' and a 6-dimension scorecard to ensure output aligns with brand voice and safety policies.
Audit Metadata