T09 · Insecure Skill Coding Practices
- Location
scripts/deconstructor.py:119- Finding
Untrusted Video Content Is Directly Embedded into Model Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent Gemini-based video ad analysis helper, with some privacy and reliability caveats but no hidden persistence, privilege escalation, destructive behavior, or deceptive data flow found.
Install only in an isolated Python environment with pinned dependencies, use a least-privileged Google service account, and avoid sending confidential or unreleased creatives unless your Gemini/Vertex AI data handling terms allow it. Treat generated JSON and text as untrusted analysis output, especially for competitor ads that may contain prompt-injection text.
scripts/deconstructor.py:119Untrusted Video Content Is Directly Embedded into Model Instructions
SKILL.md:31Third-Party Dependency Is Installed Without Version or Integrity Pinning
The code broadly matches the stated purpose of deconstructing video ads into marketing dimensions using Gemini AI. However, the declared description specifically promises extraction of hooks, social proof, CTAs, target audience, emotional triggers, and urgency tactics, while the actual DIMENSIONS list does not include explicit social_proof or call_to_action analysis. Although CTA may appear in the generated summary and social proof might be indirectly covered by 'credibility', those capabilities are not actually implemented as first-class deconstruction dimensions in this code path. Conversely, the code prominently analyzes several other dimensions not mentioned in the description, such as problem, aspiration/transformation, narrative flow, and visual format. This is a moderate description-behavior mismatch rather than a severe one, because the primary purpose still aligns.
The declared description promises a marketing-analysis skill that deconstructs ad creatives into persuasive dimensions using Gemini AI. However, the supplied code chunk only contains a simple data model for holding extracted video content. It supports a lower-level video extraction pipeline but does not itself perform ad analysis, AI inference, or marketing attribute extraction. This is a materially different primary purpose from the declared behavior, so it should be flagged as a mismatch.
The declared description says the skill analyzes video ad creatives with Gemini AI and extracts multiple advertising/marketing attributes. However, the supplied code chunk contains only infrastructure for loading and formatting prompt templates from markdown files. It does not process videos, call Gemini or any AI service, extract ad features, or perform competitor ad analysis. While prompt management could be a supporting component in a larger system, this code chunk’s actual behavior is materially different from the declared primary purpose, so this should be flagged as a mismatch.
Without declared permissions the skill's intent is opaque and cannot be validated.
The description is broad enough that an orchestrator could invoke this skill for generic ad-analysis requests without clear user intent boundaries. Over-broad triggering can route sensitive or irrelevant media/transcripts to an external AI service unexpectedly, creating privacy, cost, and workflow-integrity risks.
The example trigger phrase 'Deconstruct this competitor's ad' is open-ended and may encourage invocation on any ad-related request without confirming scope, consent, or content handling expectations. In agent environments, vague triggers increase the chance of unintended data processing or automatic external model use on user-provided media.
The code sends transcript, scene, and text-overlay data to an external Gemini service via generate_content without any visible consent, warning, or data-classification check. Even if the content is 'just ads,' extracted media may still contain sensitive or proprietary information, and transmitting it to a third party can violate privacy, contractual, or compliance expectations.
The deconstruction loop repeatedly sends the extracted ad content and derived summary to Gemini for each marketing dimension, multiplying data exposure to an external provider. This increases privacy and data-governance risk because the same content is transmitted many times, broadening opportunities for retention, leakage, or policy noncompliance.
No suspicious patterns detected.