Back to skill

Security audit

Microsoft Ads MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is for legitimate Microsoft Ads management, but it asks users to install unpinned third-party server code that can use ad credentials and modify live campaigns with potential spend.

Review before installing. Use a pinned, audited version of the MCP server in an isolated environment, authorize only a least-privilege Microsoft Ads identity, avoid administrator credentials, and require human confirmation before activating campaigns, changing budgets, publishing ads, or exporting reports.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:24
Finding

Unpinned Remote Dependency Installed from a Mutable Source

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: microsoft-ads-mcp
description: Create and manage Microsoft Advertising campaigns (Bing Ads / DuckDuckGo Ads) via MCP server - campaigns, ad groups, keywords, ads, and reporting
metadata: {"clawdbot":{"emoji":"📢","requires":{"commands":["mcporter"]},"homepage":"https://github.com/Duartemartins/microsoft-ads-mcp-server"}}
---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents commands that create campaigns, ad groups, keywords, ads, and activate campaigns, but it does not clearly warn that these actions can immediately modify a live advertising account and incur real spend. In an agentic context, users may treat examples as low-risk test steps, increasing the chance of unintended financial loss or unauthorized external account changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The reporting section exposes search-query and geographic report capabilities without warning that outputs may contain sensitive marketing intelligence, user intent data, or location-derived information. In practice, this can lead to over-collection, mishandling, or unsafe sharing of potentially sensitive account data by agents or users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.