Back to skill

Security audit

Ads Manager Claw

Security checks for vulnerabilities and agentic risk

Overview

This ad-management skill is coherent, but it asks for sensitive ad-platform credentials in chat and can make live campaign, budget, deletion, audience, and posting changes with unclear safeguards.

Install only if you are comfortable giving an agent write-level advertising access. Do not paste access tokens, refresh tokens, client secrets, API secrets, or customer lists into chat; use a secure OAuth or secret-store flow instead, prefer read-only credentials for reporting, and require explicit confirmation before budget changes, activation, deletion, audience uploads, or posting content.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:50
Finding

Advertising platform credentials are requested directly through the conversation

Content
View full analysis
"Which platform are you running ads on? Meta, Google, or something else?" Then: > "Please share your Ad Account ID and access token — only used for this session." ``` The associated credential guide also directs users to obtain secrets that may subsequently be shared with the agent: ```markdown ## Google Ads Google Ads API requires more setup than others. You'll need: - **Developer Token** (from your Google Ads Manager account) - **Customer ID** (your Google Ads account number, like `123-456-7890`) - **OAuth2 credentials** (Client ID, Client Secret, Refresh Token) ``` ```markdown ## X (Twitter) Ads 1. Go to [developer.twitter.com](https://developer.twitter.com) 2. Apply for a developer account (standard access is usually approved within 1–2 days) 3. Create a new Project and App 4. Under your App settings, go to **Keys and Tokens** 5. Generate your **API Key**, **API Secret**, **Access Token**, and **Access Token Secret** 6. Make sure your app has **Read and Write** permissions enabled 7. Your **Ad Account ID** is found at [ads.twitter.com](https://ads.twitter.com) → click your account name at the top ``` ### Technical Analysis The skill explicitly asks users to paste an advertising account access token into the agent conversation. The related guides identify additional long-lived and high-value credentials, including client secrets, refresh tokens, developer tokens, API secrets, and write-enabled access tokens. A conversation is not established as a secure secret-entry channel. Depending on the host environment, submitted credentials may be ...[truncated 2152 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/credential-guides.md:26
Finding

Meta secrets are transmitted in URL query strings

Content
View full analysis
⚠️ For a long-lived token (doesn't expire every hour), exchange your short-lived token: > `GET https://graph.facebook.com/oauth/access_token?grant_type=fb_exchange_token&client_id={app_id}&client_secret={app_secret}&fb_exchange_token={short_token}` ``` The Meta API reference also recommends query-string authentication: ```markdown Base URL: `https://graph.facebook.com/v21.0/` Auth: Append `access_token={token}` to all requests (or use Authorization header) ``` Examples repeat this pattern: ```markdown GET `/{ad_account_id}/insights` ``` ?fields=campaign_name,impressions,clicks,ctr,spend,cpc,cpm,actions,cost_per_action_type &date_preset=last_7d &level=campaign &access_token=TOKEN ``` ``` ```markdown Use the Search API to find interest IDs: GET `https://graph.facebook.com/v21.0/search?type=adinterest&q=yoga&access_token=TOKEN` ``` ### Technical Analysis Authentication secrets embedded in URLs can be copied into multiple systems outside the intended API request. Full URLs are commonly captured in browser history, reverse-proxy logs, gateway logs, monitoring systems, debugging output, command history, screenshots, and copied transcripts. The token-exchange URL is especially sensitive because it contains both the Meta application secret and the short-lived user token. Exposure of either value is damaging; exposure of both may facilitate token exchange and continued account access. TLS protects a request while it is transmitted but does not prevent endpoint URLs from being retained before encryption or after termination. Using a URL query parameter ...[truncated 1482 chars]
Remediation
View remediation
` headers for Meta API requests wherever supported. 3. Use a protected POST body for token exchange where the platform supports it, following the current official Meta OAuth documentation. 4. Ensure HTTP clients, proxies, gateways, and application logs redact authorization headers and sensitive request bodies. 5. Prohibit credentials in browser-address-bar examples, copied links, command-line arguments, and diagnostic messages. 6. Add automated secret scanning for `access_token`, `client_secret`, `fb_exchange_token`, and similar query parameters. 7. Rotate any credentials that may already have been used in the documented URL format. 8. Replace literal token examples with opaque secret-store references and clearly state that secrets must never be pasted into chat or URLs. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/credential-guides.md:17
Finding

Meta credentials are granted broad management permissions without task-specific least privilege

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (24)

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

The explicit request for an 'access token' is credential access behavior and is especially risky because the skill appears capable of taking ad account actions. An exposed token could let an attacker view data, modify campaigns, spend budget, or lock out legitimate operators depending on scopes.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
Then:

> "Please share your Ad Account ID and access token — only used for this session."

---

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Requesting an access token in plain text is a direct sensitive-data collection flaw. If a user complies, the token can be exposed through logs, transcripts, analytics pipelines, or other agents, allowing unauthorized access to ad accounts and campaign controls.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 353)May include surrounding context.

md
# Step 5 — Output Style

Always respond with:

1. 📊 Performance Summary  
2. ⚠️ Issues Detected

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/credential-guides.md (reported line 22)May include surrounding context.

md
2. Click **My Apps** → **Create App** → choose **Business** type
3. Add the **Marketing API** product to your app
4. Go to **Tools** → **Graph API Explorer**
5. Select your app and click **Generate Access Token**
6. Select these permissions: `ads_management`, `ads_read`, `business_management`
7. Copy the token shown

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/meta.md (reported line 210)May include surrounding context.

md
| Error code | Plain English meaning |
|---|---|
| `100` | Something is missing or wrong in the request — check required fields |
| `200` | Permission error — your access token doesn't have the right permissions |
| `190` | Access token expired — generate a new one |
| `2635` | Daily budget too low — minimum is usually $1/day |
| `1487398` | Special ad category required (housing, credit, employment, politics) |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/snapchat.md (reported line 239)May include surrounding context.

md
| Error code | Plain English meaning |
|---|---|
| `100` | Something is missing or wrong in the request — check required fields |
| `200` | Permission error — your access token doesn't have the right permissions |
| `190` | Access token expired — generate a new one |
| `2635` | Daily budget too low — minimum is usually $1/day |
| `1487398` | Special ad category required (housing, credit, employment, politics) |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/meta.md (reported line 211)May include surrounding context.

md
|---|---|
| `100` | Something is missing or wrong in the request — check required fields |
| `200` | Permission error — your access token doesn't have the right permissions |
| `190` | Access token expired — generate a new one |
| `2635` | Daily budget too low — minimum is usually $1/day |
| `1487398` | Special ad category required (housing, credit, employment, politics) |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/credential-guides.md (reported line 10)May include surrounding context.

md
# X (Twitter) Ads API Reference

Base URL: `https://ads-api.x.com/12/`
Auth: OAuth 1.0a (use all 4 credentials: API Key, API Secret, Access Token, Access Token Secret)

> ⚠️ Important limitations:
> - Funding instruments (credit cards) CANNOT be created via API — must be set up at ads.twitter.com first

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/credential-guides.md (reported line 17)May include surrounding context.

md
# X (Twitter) Ads API Reference

Base URL: `https://ads-api.x.com/12/`
Auth: OAuth 1.0a (use all 4 credentials: API Key, API Secret, Access Token, Access Token Secret)

> ⚠️ Important limitations:
> - Funding instruments (credit cards) CANNOT be created via API — must be set up at ads.twitter.com first

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/credential-guides.md (reported line 62)May include surrounding context.

md
# X (Twitter) Ads API Reference

Base URL: `https://ads-api.x.com/12/`
Auth: OAuth 1.0a (use all 4 credentials: API Key, API Secret, Access Token, Access Token Secret)

> ⚠️ Important limitations:
> - Funding instruments (credit cards) CANNOT be created via API — must be set up at ads.twitter.com first

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/snapchat.md (reported line 6)May include surrounding context.

md
# X (Twitter) Ads API Reference

Base URL: `https://ads-api.x.com/12/`
Auth: OAuth 1.0a (use all 4 credentials: API Key, API Secret, Access Token, Access Token Secret)

> ⚠️ Important limitations:
> - Funding instruments (credit cards) CANNOT be created via API — must be set up at ads.twitter.com first

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/x-ads.md (reported line 4)May include surrounding context.

md
# X (Twitter) Ads API Reference

Base URL: `https://ads-api.x.com/12/`
Auth: OAuth 1.0a (use all 4 credentials: API Key, API Secret, Access Token, Access Token Secret)

> ⚠️ Important limitations:
> - Funding instruments (credit cards) CANNOT be created via API — must be set up at ads.twitter.com first

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest promises the skill will recommend actions before executing anything, but later instructions direct the agent to execute campaign actions. This mismatch can mislead users and downstream systems about the skill's operational safety, increasing the chance of unapproved spend changes, pauses, or campaign creation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file repeatedly frames the skill as India-optimized and instructs the agent to use rupee-based profitability and India-specific ad assumptions. This can amount to a locale policy violation because it forces a specific locale and business context without explicit user opt-in beyond branding, and the operational instructions say to always explain in ₹ terms.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill asks the user to paste an ad account access token directly into conversation text and provides only a weak assurance that it is 'only used for this session'. Collecting credentials in plain language exposes sensitive secrets to chat logs, retention systems, prompt injection surfaces, and accidental disclosure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documentation gives inconsistent guidance about execution boundaries: earlier sections say to confirm before actions and the manifest says it recommends before executing, but the final behavior says to 'Execute'. In an agent setting, conflicting instructions can cause unsafe autonomous changes to live ad campaigns without clear user consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction to always explain actions in rupee terms imposes a fixed currency/locale on all users. Because no alternative locale or currency choice is offered, this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide instructs users to generate and copy Meta access tokens, including exchanging for a long-lived token, but does not warn that these tokens are highly sensitive secrets that grant ad account access. In an agent skill context, users may paste such tokens back into chat or store them insecurely, increasing the risk of unauthorized campaign changes, data access, and account abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These instructions tell users to download OAuth client JSON and obtain a refresh token, both of which are sensitive credentials that can enable persistent API access if exposed. Without guidance on secure handling, storage, and non-sharing, users may leak long-lived credentials to the agent, local files, or version control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The X Ads section walks users through generating API keys, API secrets, access tokens, and token secrets, but omits any confidentiality warning. Because these credentials can permit read/write ad actions, the absence of handling guidance makes accidental disclosure and misuse more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Snapchat Ads instructions direct users to retrieve a client secret and refresh token but provide no warning that these are long-lived secrets whose disclosure can lead to unauthorized account access. In a support-oriented skill, omission of secure-handling guidance materially raises the chance users will expose them to the system or third parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The reference explicitly documents setting campaign status to REMOVED and notes it as a permanent delete, but it does not provide a strong operational warning, confirmation requirement, or guidance to prefer PAUSED for reversible changes. In an ad-management skill that may be used to execute account changes, this increases the risk of accidental irreversible campaign deletion, causing loss of campaign history, delivery, and business continuity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation instructs users to create Custom Audiences from email lists and upload hashed emails, but it does not warn about consent, lawful basis, platform policy compliance, or secure handling of customer data. In an ads-management skill, this omission can lead to privacy violations, misuse of customer PII, and noncompliant audience uploads even if the API usage itself is legitimate.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/x-ads.md (reported line 115)May include surrounding context.

text

To create a new tweet with a card (image + link):
POST `https://api.x.com/2/tweets`
```json
{
  "text": "Shop our Summer Sale — up to 50% off! 🛍️",

Static analysis

No suspicious patterns detected.