ad-copy

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONPERSISTENCEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to create directories and write files to hidden home directory paths. Evidence: SKILL.md contains explicit instructions to create the ~/.claude/ad-profiles/ folder.
  • [PERSISTENCE]: The skill implements a persistence mechanism by saving brand profiles in a hidden directory designed to survive skill updates. Evidence: SKILL.md specifies saving data to ~/.claude/ad-profiles/ so they 'survive updates'.
  • [DATA_EXFILTRATION]: The skill collects and persists sensitive business data (name, brand, product, price, audience, pain points) in local files. Evidence: SKILL.md Step 0 onboarding interview collects 13 detailed business attributes.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to the ingestion of untrusted raw customer language into persistent profiles. Evidence: 1. Ingestion points: Testimonials and reviews are collected in SKILL.md (Step 0 and Step 1). 2. Boundary markers: Absent. 3. Capability inventory: Writing to sensitive local paths (~/.claude/ad-profiles/). 4. Sanitization: Absent.
  • [EXTERNAL_DOWNLOADS]: The documentation includes a URL flagged as a known scam site by automated scanners. Evidence: reference/writing-ad-copy-101.md contains the link secure.medilisk.com/hemorrhoids-cream-article, which is identified as an EshopScam site.
Recommendations
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 14, 2026, 08:24 AM
Security Audit — agent-trust-hub — ad-copy