T09 · Insecure Skill Coding Practices
- Location
SKILL.md:50- Finding
Advertising platform credentials are requested directly through the conversation
- Content
View full analysis
"Which platform are you running ads on? Meta, Google, or something else?" Then: > "Please share your Ad Account ID and access token — only used for this session." ``` The associated credential guide also directs users to obtain secrets that may subsequently be shared with the agent: ```markdown ## Google Ads Google Ads API requires more setup than others. You'll need: - **Developer Token** (from your Google Ads Manager account) - **Customer ID** (your Google Ads account number, like `123-456-7890`) - **OAuth2 credentials** (Client ID, Client Secret, Refresh Token) ``` ```markdown ## X (Twitter) Ads 1. Go to [developer.twitter.com](https://developer.twitter.com) 2. Apply for a developer account (standard access is usually approved within 1–2 days) 3. Create a new Project and App 4. Under your App settings, go to **Keys and Tokens** 5. Generate your **API Key**, **API Secret**, **Access Token**, and **Access Token Secret** 6. Make sure your app has **Read and Write** permissions enabled 7. Your **Ad Account ID** is found at [ads.twitter.com](https://ads.twitter.com) → click your account name at the top ``` ### Technical Analysis The skill explicitly asks users to paste an advertising account access token into the agent conversation. The related guides identify additional long-lived and high-value credentials, including client secrets, refresh tokens, developer tokens, API secrets, and write-enabled access tokens. A conversation is not established as a secure secret-entry channel. Depending on the host environment, submitted credentials may be ...[truncated 2152 chars]- Remediation
View remediation
