Back to skill

Security audit

ad-library-scraper

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed ad-library lookup connector, with the main cautions being third-party ToolRouter data handling and an unpinned npm MCP bridge command.

Install only if you are comfortable sending ad research requests through ToolRouter. Avoid submitting sensitive business plans or private customer data in prompts, and consider pinning or reviewing the `toolrouter-mcp` package before using the Claude Code setup path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The skill directs the agent/client to connect to an external MCP endpoint at https://api.toolrouter.com/mcp, which transmits user queries and retrieved ad-library data to a third-party service outside the local trust boundary. In this skill's context, external transmission is core functionality, but it still introduces data exposure, logging, dependency, and trust risks if users submit sensitive prompts or if the service is compromised.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
## Installation

Install with `pnpm dlx skills add Humanleap/agent-skills --skill ad-library-scraper`. Connect the client's remote MCP server to `https://api.toolrouter.com/mcp` (Claude: Customize → Connectors → Add custom connector; Claude Code: `claude mcp add toolrouter -- npx -y toolrouter-mcp`). Setup: https://toolrouter.com/docs/markdown/quickstart.

## Hard Rules

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs users to install and run an MCP component via npx -y toolrouter-mcp without pinning a specific version or integrity-checked artifact. That creates a supply-chain risk: future package updates or a compromised publisher account could cause different code to execute than the skill was originally reviewed against.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.