ad-campaign-writer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's behavior is consistent with its stated purpose and it lacks any malicious functionality.
  • [PROMPT_INJECTION]: The instructions do not contain attempts to override agent behavior, bypass safety protocols, or extract system prompts.
  • [DATA_EXFILTRATION]: There are no network requests (curl, wget, fetch) or access attempts to sensitive system files like SSH keys or environment variables.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform any remote package installations or script execution.
  • [OBFUSCATION]: The content is clear and does not use Base64, zero-width characters, or homoglyphs to hide information.
  • [DYNAMIC_EXECUTION]: No use of eval, exec, or the load-time command execution syntax (!command) was found.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests local data from the knowledge/ directory but has no high-privilege capabilities that could be exploited. 1. Ingestion points: files in knowledge/ directory (SKILL.md). 2. Boundary markers: absent. 3. Capability inventory: local file-write to output/ directory (SKILL.md). 4. Sanitization: absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:28 AM
Security Audit — agent-trust-hub — ad-campaign-writer