ad-copy
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONPERSISTENCEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to create directories and write files to hidden home directory paths. Evidence:
SKILL.mdcontains explicit instructions to create the~/.claude/ad-profiles/folder. - [PERSISTENCE]: The skill implements a persistence mechanism by saving brand profiles in a hidden directory designed to survive skill updates. Evidence:
SKILL.mdspecifies saving data to~/.claude/ad-profiles/so they 'survive updates'. - [DATA_EXFILTRATION]: The skill collects and persists sensitive business data (name, brand, product, price, audience, pain points) in local files. Evidence:
SKILL.mdStep 0 onboarding interview collects 13 detailed business attributes. - [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to the ingestion of untrusted raw customer language into persistent profiles. Evidence: 1. Ingestion points: Testimonials and reviews are collected in
SKILL.md(Step 0 and Step 1). 2. Boundary markers: Absent. 3. Capability inventory: Writing to sensitive local paths (~/.claude/ad-profiles/). 4. Sanitization: Absent. - [EXTERNAL_DOWNLOADS]: The documentation includes a URL flagged as a known scam site by automated scanners. Evidence:
reference/writing-ad-copy-101.mdcontains the linksecure.medilisk.com/hemorrhoids-cream-article, which is identified as an EshopScam site.
Recommendations
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata