ad-creative

Pass

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest advertising performance data from external sources (such as CSV files, manual pastes, or API outputs) to iterate on creative variations. This creates a surface for indirect prompt injection where untrusted data from an advertising report could attempt to influence agent behavior. However, this data processing is a primary purpose of the skill and no specific malicious payloads were identified.\n- [COMMAND_EXECUTION]: The skill utilizes local CLI tools and code-based rendering engines to perform its tasks. It references the execution of scripts like 'node tools/clis/google-ads.js' and the use of the Remotion framework to render video ads from React components. These operations are aligned with the skill's stated purpose of automated ad production.\n- [EXTERNAL_DOWNLOADS]: The skill references and provides integration guidance for numerous third-party AI services and external repositories. These include well-known providers such as Google Gemini, OpenAI, ElevenLabs, and Ideogram, as well as the open-source 'voicebox' tool on GitHub. All referenced external sources are reputable services or standard developer tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 22, 2026, 10:50 PM
Security Audit — agent-trust-hub — ad-creative