ads-creative

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [SAFE]: No executable code or external scripts are included with this skill. It is composed of static markdown instructions and YAML metadata.
  • [SAFE]: No credentials, secrets, or sensitive file paths are accessed or hardcoded within the instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill allows the agent to fetch content from external URLs provided by the user to inform the creative brief. This is an inherent attack surface for indirect prompt injection where external content could attempt to override agent instructions. This functionality is core to the skill's purpose and contains no specific malicious logic.
  • Ingestion points: WebFetch tool call in Step 1 of SKILL.md.
  • Boundary markers: Absent; instructions do not specify delimiters for external content.
  • Capability inventory: Uses WebFetch for network retrieval and writes output to a local markdown file.
  • Sanitization: Not specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:50 PM
Security Audit — agent-trust-hub — ads-creative