Ad Creative Analysis

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward ad-creative analyzer that inspects a user-provided folder, so it is acceptable when used only on intended ad files.

Install if you want an agent to review ad creatives from a local folder. Use a dedicated folder containing only the images, videos, transcripts, and metadata you intend to analyze, not a Downloads, Desktop, client, or project root directory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad and overlap with ordinary user requests such as analyzing ads, scoring creatives, or evaluating a folder, which can cause the skill to activate in situations the user did not explicitly intend. That increases the chance of the agent performing local file enumeration and content analysis on unintended data sources, especially when combined with directory-based processing.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill directs the agent to list all files in a provided directory and read adjacent transcript and metadata files without any privacy notice, scope limitation, or confirmation step. If activated on a sensitive or overly broad path, this could expose filenames, transcripts, and business metadata from local storage beyond what the user expected to share.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal