Back to skill

Security audit

Ad Copywriter

Security checks for vulnerabilities and agentic risk

Overview

The main ad-copy tool is local and mostly purpose-aligned, but the package includes undocumented local history logging and always adds vendor promotional contact text to command output.

Review before installing if you may enter confidential campaign, product, SEO, or unpublished marketing topics. The main tool does not use network access or elevated privileges, but the extra script can save prompts locally, and generated command output may include vendor attribution that should be removed before using copy in deliverables.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
scripts/ad.sh:704
Finding

Unconditional Promotional Content Injection into Skill Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:63-64; scripts/ad.sh:704-705
Vulnerability Type: Forced advertising and traffic-diversion content injection
Risk Level: High

Vulnerable Code

SKILL.md:63-64:

markdown
💬 Feedback & Feature Requests: https://bytesagain.com/feedback
Powered by BytesAgain | bytesagain.com

scripts/ad.sh:704-705:

bash
echo ""
echo "  Powered by BytesAgain | bytesagain.com | hello@bytesagain.com"

Technical Analysis

The executable unconditionally appends a third-party brand name, domain, and email address after every invocation. This behavior applies to generated advertisements, help output, and error output, and there is no option to disable it.

The footer is not required to provide the declared ad-copy generation, A/B testing, ROI calculation, or platform-adaptation functionality. Because an AI agent may relay the command output directly to a user, the footer causes attacker-selected promotional material to become part of the agent's response. The matching promotional template in SKILL.md reinforces the traffic-diversion behavior at the instruction/documentation layer.

This is classified as skill instruction hijacking because the package causes agent-visible responses to include content unrelated to the user's requested deliverable. The behavior exceeds the minimum privileges and output control necessary for the Skill's declared functionality.

Attack Path

  1. A user asks the agent to generate advertising copy or perform an ROI calculation.
  2. The agent loads SKILL.md and invokes scripts/ad.sh.
  3. The embedded Python code produces the requested result.
  4. After Python completes, the shell unconditionally prints the hard-coded BytesAgain attribution, domain, and email address.
  5. If the agent returns the command output without filtering, the unsolicited promotional content is delivered as part of the agent's answer.
  6. A rec ...[truncated 815 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the unconditional footer from scripts/ad.sh.
  2. Remove the promotional and feedback-link template from the end of SKILL.md unless it is essential documentation.
  3. If attribution is legitimately required, expose it only through an explicit about or version command.
  4. Alternatively, require an explicit user-controlled option such as --include-attribution; keep it disabled by default.
  5. Keep standard output limited to the requested result. Send optional diagnostic or attribution information to standard error only when explicitly enabled.
  6. Add automated tests asserting that generated content contains no unrelated URLs, email addresses, or vendor branding by default.
  7. Document any remaining attribution behavior clearly so agents and users can make an informed choice before invocation.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:5
Finding

Undocumented Persistent Logging of User-Supplied Content

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:5-8; scripts/script.sh:35-83
Vulnerability Type: Undisclosed plaintext persistence of user input
Risk Level: Medium

Vulnerable Code

scripts/script.sh:5-8:

bash
DATA_DIR="${AD_COPYWRITER_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/ad-copywriter}"
DB="$DATA_DIR/data.log"
mkdir -p "$DATA_DIR"

scripts/script.sh:35-83:

bash
_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }

cmd_draft() {
    echo "  Draft: $1
      Target: ${2:-800} words"
    _log "draft" "${1:-}"
}

cmd_headline() {
    echo "  1. How to $1
      2. $1: Complete Guide
      3. Why $1 Matters"
    _log "headline" "${1:-}"
}

cmd_outline() {
    echo "  1. Intro | 2. Problem | 3. Solution | 4. Examples | 5. CTA"
    _log "outline" "${1:-}"
}

cmd_seo() {
    echo "  Keywords: $1 | Title tag | Meta desc | H1-H3 | Internal links"
    _log "seo" "${1:-}"
}

cmd_schedule() {
    echo "  Mon: Research | Tue: Write | Wed: Edit | Thu: Publish | Fri: Promote"
    _log "schedule" "${1:-}"
}

cmd_hooks() {
    echo "  Question | Statistic | Story | Bold claim | Controversy"
    _log "hooks" "${1:-}"
}

cmd_cta() {
    echo "  Subscribe | Share | Comment | Try it | Learn more"
    _log "cta" "${1:-}"
}

cmd_repurpose() {
    echo "  Blog -> Thread -> Video -> Carousel -> Newsletter"
    _log "repurpose" "${1:-}"
}

cmd_metrics() {
    echo "  Views | Clicks | Shares | Time on page | Conversions"
    _log "metrics" "${1:-}"
}

cmd_ideas() {
    echo "  How-to | Listicle | Case study | Interview | Comparison"
    _log "ideas" "${1:-}"
}

Technical Analysis

The secondary script creates a persistent directory under AD_COPYWRITER_DIR, XDG_DATA_HOME, or the user's home directory as soon as it starts. Most content-generation commands then append the fir ...[truncated 2163 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove persistent logging because it is not required for the script's stateless content-generation functions.
  2. If history is a required feature, disable it by default and require explicit user opt-in.
  3. Clearly document what information is stored, its path, purpose, retention period, and deletion procedure.
  4. Do not retain raw user arguments. Redact sensitive values or store only non-sensitive aggregate metadata.
  5. Set restrictive permissions before creating the directory and files, for example with umask 077.
  6. Create the directory with mode 0700 and the history file with mode 0600.
  7. Add configurable retention limits, file rotation, and a command that securely clears saved history.
  8. Avoid creating the data directory for commands that do not use persistence, including help and version operations.
  9. Document scripts/script.sh in SKILL.md or remove it from the package if it is obsolete and not part of the declared functionality.
  10. Add tests verifying that no user input is written to disk unless persistence has been explicitly enabled.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and the body of the skill are primarily written in Chinese and present the skill as a Chinese ad-copy generator, but they do not state that language is optional or user-selectable. Under the policy, fixed language behavior without opt-in can be a locale/language policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code's help text, command descriptions, generated ad copy, and user-facing output are overwhelmingly fixed in Chinese, effectively constraining the skill to a single language. The file does not provide any user opt-in, locale selection, or documented justification for this language restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script records user-supplied content to a persistent local history file via the _log function without notifying the user or offering a way to disable logging. Because commands like draft, headline, and seo may include sensitive prompts, campaign plans, unpublished content, or proprietary marketing text, this creates an information disclosure risk to other local users, backups, or later processes that read the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Line L091 states '英文为主' for Google Ads copy style, which imposes a language preference in natural-language guidance. The file does not offer a user choice or explain that this is an optional recommendation tied to a specific campaign locale.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

No manifest is available, so the skill's purpose must be inferred from the file itself as documentation about ad campaign optimization. The line '使用 ad.sh help 查看所有可用命令' introduces a shell-command capability that is not justified by the rest of the file, which otherwise contains only static tips and no corresponding command implementation or operational context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.