ad-creative
Fail
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The file
references/generative-tools.mdprovides instructions to clone a third-party GitHub repository (github.com/jamiepine/voicebox) and execute its setup and development scripts (make setup && make dev). This involves downloading and running unverified code from an external source. - [REMOTE_CODE_EXECUTION]: The skill recommends using
npx create-video@latestto bootstrap projects. Usingnpxwith unversioned packages downloads and executes code from the NPM registry at runtime, which can be a vector for supply chain attacks. - [COMMAND_EXECUTION]: The skill executes local JavaScript scripts and CLI tools (e.g.,
node tools/clis/google-ads.js) to interact with ad platform APIs and retrieve performance metrics. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through its "Iterate from Performance Data" mode. It ingests untrusted data from CSV files, clipboard pastes, or API outputs which are then used to influence the agent's analysis and the generation of new ad variations.
- Ingestion points: CSV files, manual pastes, and API outputs mentioned in
SKILL.md. - Boundary markers: None identified; there are no instructions to the agent to ignore or delimit instructions found within the ingested data.
- Capability inventory: The agent can execute CLI tools, write files, and generate/execute React code for video rendering.
- Sanitization: No evidence of input validation or sanitization of the performance data before it is processed.
- [REMOTE_CODE_EXECUTION]: The skill suggests a workflow where AI generates React components (using Remotion) which are then programmatically rendered into video files. If the code generation process is influenced by malicious input from the performance data iteration step, it could lead to the execution of arbitrary code during the rendering process.
Recommendations
- AI detected serious security threats
Audit Metadata