T08 · Insecure Dependencies
- Location
SKILL.md:24- Finding
Unpinned Remote Dependency Installed from a Mutable Source
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is for legitimate Microsoft Ads management, but it asks users to install unpinned third-party server code that can use ad credentials and modify live campaigns with potential spend.
Review before installing. Use a pinned, audited version of the MCP server in an isolated environment, authorize only a least-privilege Microsoft Ads identity, avoid administrator credentials, and require human confirmation before activating campaigns, changing budgets, publishing ads, or exporting reports.
SKILL.md:24Unpinned Remote Dependency Installed from a Mutable Source
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
---
name: microsoft-ads-mcp
description: Create and manage Microsoft Advertising campaigns (Bing Ads / DuckDuckGo Ads) via MCP server - campaigns, ad groups, keywords, ads, and reporting
metadata: {"clawdbot":{"emoji":"📢","requires":{"commands":["mcporter"]},"homepage":"https://github.com/Duartemartins/microsoft-ads-mcp-server"}}
---
The skill documents commands that create campaigns, ad groups, keywords, ads, and activate campaigns, but it does not clearly warn that these actions can immediately modify a live advertising account and incur real spend. In an agentic context, users may treat examples as low-risk test steps, increasing the chance of unintended financial loss or unauthorized external account changes.
The reporting section exposes search-query and geographic report capabilities without warning that outputs may contain sensitive marketing intelligence, user intent data, or location-derived information. In practice, this can lead to over-collection, mishandling, or unsafe sharing of potentially sensitive account data by agents or users.
No suspicious patterns detected.