ad-creative
Pass
Audited by Gen Agent Trust Hub on Mar 22, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest advertising performance data from external sources (such as CSV files, manual pastes, or API outputs) to iterate on creative variations. This creates a surface for indirect prompt injection where untrusted data from an advertising report could attempt to influence agent behavior. However, this data processing is a primary purpose of the skill and no specific malicious payloads were identified.\n- [COMMAND_EXECUTION]: The skill utilizes local CLI tools and code-based rendering engines to perform its tasks. It references the execution of scripts like 'node tools/clis/google-ads.js' and the use of the Remotion framework to render video ads from React components. These operations are aligned with the skill's stated purpose of automated ad production.\n- [EXTERNAL_DOWNLOADS]: The skill references and provides integration guidance for numerous third-party AI services and external repositories. These include well-known providers such as Google Gemini, OpenAI, ElevenLabs, and Ideogram, as well as the open-source 'voicebox' tool on GitHub. All referenced external sources are reputable services or standard developer tools.
Audit Metadata