Back to skill

Security audit

AB-Directolog-Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Yandex.Direct automation helper, but it handles live ad-account authority and OAuth credentials with insufficient safeguards.

Install only if you are comfortable giving an agent access to a live Yandex.Direct account. Use restricted OAuth credentials, test on non-production or low-budget accounts first, avoid running mutating examples casually, and do not let the agent store refresh tokens or complete OAuth responses in markdown memory or logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
examples/token-refresh.sh:15
Finding

OAuth Access Token Disclosed Through Standard Output

Content
View full analysis
Remediation
View remediation
&2 exit 1 } ``` 3. If diagnostic output is necessary, print only non-sensitive status information and explicitly redact token fields. 4. Configure agent runtimes, CI systems, and centralized logging tools to mask OAuth tokens and related secrets. 5. Avoid passing the token to downstream processes through command-line arguments, which may be visible in process listings. Prefer protected environment injection, standard input, or a managed secret interface. 6. Restrict access to execution logs and define short retention periods for logs that may already contain credentials. 7. Revoke and rotate any token that may have been exposed by prior script executions. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
memory/direct-memory.md:3
Finding

Long-Lived Refresh Token Stored in Auto-Saved Plaintext Agent Memory

Content
View full analysis
" refresh_token: "" # Хранить в зашифрованном виде last_token_update: "" ``` ``` `config/agent.json`, lines 12–14: ```json "memory": { "path": "./memory/direct-memory.md", "autoSave": true } ``` ### Technical Analysis The Skill instructs the agent to place a refresh token in `memory/direct-memory.md`, while the agent configuration enables automatic saving to that file. Although comments state that the token should be encrypted, the reviewed project does not implement encryption, key management, protected storage, file-permission enforcement, or a secret-reference mechanism. A Markdown file is plaintext storage unless an external encryption layer is explicitly implemented. Merely labeling a value as encrypted does not protect it. Automatic memory persistence also increases the possibility that a credential supplied during a conversation will be copied into the workspace without an explicit security decision by the user. Refresh tokens are particularly sensitive because they can be exchanged for new access tokens and generally remain ...[truncated 1852 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (36)

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

Printing the freshly issued access token is a credential exposure issue. In operational contexts such as shared terminals, CI/CD jobs, remote support sessions, or centralized log collection, this can leak a live bearer token that permits direct access to the associated Yandex resources until expiry or revocation.

Content

Scanner excerpt · examples/token-refresh.sh (reported line 19)May include surrounding context.

sh
# Извлечение access_token
ACCESS_TOKEN=$(echo "$RESPONSE" | jq -r '.access_token')
echo "New Access Token: $ACCESS_TOKEN"

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises creation and editing of live Yandex.Direct campaigns, ads, bids, and strategies without clearly warning that these operations can immediately alter production advertising configuration and spend. In an agent skill context, this omission increases the chance of unsafe use, accidental changes, or operator misunderstanding when delegating tasks to an automated agent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example command to create an ad group presents a live POST operation as a normal usage example without stating that it will modify the advertiser account. In an automation or agent setting, users may copy-paste the command assuming it is a harmless demo, leading to unintended ad object creation and possible downstream spend or configuration errors.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill documentation and user-facing examples are presented in Russian, which effectively imposes a specific language on users. There is no opt-in, alternate language option, or explanation that the skill is intentionally limited to a Russian-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

После авторизации код обменивается на токен:

bash
curl -X POST https://oauth.yandex.com/token \
  -d "grant_type=authorization_code" \
  -d "code=<CODE>" \
  -d "client_id=<CLIENT_ID>" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs storing client secrets, access tokens, refresh tokens, and account data in agent environment/files and shows memory content containing sensitive identifiers. In an agent ecosystem, memory files may be read by other skills, logged, synced, or exposed to users, which can lead to credential theft and unauthorized ad-account access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description is written entirely in Russian and presents the skill as a Russian-language expert without any indication that users may choose another language. This can violate language/locale policy when a skill implicitly constrains interaction language without explicit opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This shell script sends an authenticated POST request to the Yandex Direct API to create a new campaign, which is a state-changing remote operation. Although the comment says it is an example, the file itself provides no user-facing warning, confirmation prompt, or disclosure that running it will create resources in a live external account using the provided token.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
ACCESS_TOKEN="${YANDEX_DIRECT_ACCESS_TOKEN:-your_access_token_here}"

curl -s -X POST "https://api.direct.yandex.com/json/v5/campaigns" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
ACCESS_TOKEN="${YANDEX_DIRECT_ACCESS_TOKEN:-your_access_token_here}"

curl -s -X POST "https://api.direct.yandex.com/json/v5/campaigns" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
ACCESS_TOKEN="${YANDEX_DIRECT_ACCESS_TOKEN:-your_access_token_here}"

curl -s -X POST "https://api.direct.yandex.com/json/v5/campaigns" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 168)May include surrounding context.

md
ACCESS_TOKEN="${YANDEX_DIRECT_ACCESS_TOKEN:-your_access_token_here}"

curl -s -X POST "https://api.direct.yandex.com/json/v5/campaigns" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
ACCESS_TOKEN="${YANDEX_DIRECT_ACCESS_TOKEN:-your_access_token_here}"

curl -s -X POST "https://api.direct.yandex.com/json/v5/campaigns" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · examples/create-campaign.sh (reported line 6)May include surrounding context.

sh
ACCESS_TOKEN="${YANDEX_DIRECT_ACCESS_TOKEN:-your_access_token_here}"

curl -s -X POST "https://api.direct.yandex.com/json/v5/campaigns" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · examples/get-campaigns.sh (reported line 6)May include surrounding context.

sh
ACCESS_TOKEN="${YANDEX_DIRECT_ACCESS_TOKEN:-your_access_token_here}"

curl -s -X POST "https://api.direct.yandex.com/json/v5/campaigns" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · examples/get-keywords.sh (reported line 7)May include surrounding context.

sh
ACCESS_TOKEN="${YANDEX_DIRECT_ACCESS_TOKEN:-your_access_token_here}"

curl -s -X POST "https://api.direct.yandex.com/json/v5/campaigns" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · examples/get-reports.sh (reported line 8)May include surrounding context.

sh
ACCESS_TOKEN="${YANDEX_DIRECT_ACCESS_TOKEN:-your_access_token_here}"

curl -s -X POST "https://api.direct.yandex.com/json/v5/campaigns" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · examples/create-campaign.sh (reported line 6)May include surrounding context.

sh
ACCESS_TOKEN="${YANDEX_DIRECT_ACCESS_TOKEN:-your_access_token_here}"

curl -s -X POST "https://api.direct.yandex.com/json/v5/campaigns" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · examples/get-campaigns.sh (reported line 6)May include surrounding context.

sh
ACCESS_TOKEN="${YANDEX_DIRECT_ACCESS_TOKEN:-your_access_token_here}"

curl -s -X POST "https://api.direct.yandex.com/json/v5/campaigns" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script sends an authenticated HTTP request to the Yandex.Direct API using a bearer token from an environment variable, but it provides no user-facing warning, confirmation, or explanatory comment about transmitting account-scoped data to an external service. The brief Russian comment describes the example's purpose, but it does not disclose the security-sensitive use of credentials or remote data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script reads a sensitive credential from YANDEX_DIRECT_ACCESS_TOKEN and immediately uses it in an Authorization header for an external HTTP request. There is no confirmation prompt, warning comment, or user-facing message explaining that a credential will be used and transmitted.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · examples/get-keywords.sh (reported line 7)May include surrounding context.

sh
ACCESS_TOKEN="${YANDEX_DIRECT_ACCESS_TOKEN:-your_access_token_here}"
CAMPAIGN_ID="${1:-123456}"

curl -s -X POST "https://api.direct.yandex.com/json/v5/keywords" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \
  -d "{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This shell script reads a credential from the YANDEX_DIRECT_ACCESS_TOKEN environment variable and sends it as a Bearer token in an HTTP request. There is no prompt, echo/log disclosure, or surrounding documentation in this file warning the user that a credential will be used and data will be sent to an external API.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.