ad-creative

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill instructions require the agent to read 'marketing-context.md' to gather project details without using delimiters or sanitization instructions. This ingestion point is vulnerable to embedded instructions that could override agent behavior during the creative process. * Ingestion points: marketing-context.md (SKILL.md) * Boundary markers: Absent * Capability inventory: Creative text generation and platform-specific formatting * Sanitization: Absent
  • [COMMAND_EXECUTION]: Missing Script Reference. The quality checklist in SKILL.md directs the agent to run 'scripts/ad_copy_validator.py' to verify character limits. However, this script is not included in the skill package, which may result in execution failures or the agent attempting to execute an unintended script if a file with the same name exists in the environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:05 PM
Security Audit — agent-trust-hub — ad-creative