Back to skill

Security audit

Ad Copy Gen

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly an upsell with PayPal, Telegram, and crypto payment details rather than a usable ad-copy generator.

Review carefully before installing. The skill does not appear to run code or access your data, but it under-delivers on its advertised functionality and steers users to off-platform payment/contact channels for the useful content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill content is primarily a sales page and paywalled upsell rather than functional instructions or resources for ad-copy generation. This is dangerous because it misrepresents the skill’s purpose, can manipulate users or agents into commercial redirection, and creates a trust boundary violation where the advertised capability is withheld behind external payment/contact flows.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
Embedding a PayPal payment solicitation inside a skill that should generate ad copy introduces unrelated financial interaction not required for the skill’s core function. This is dangerous because users or agents may be socially engineered into making payments from within a trusted skill context, increasing phishing, fraud, and policy-bypass risk.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
The Telegram contact, PayPal link, and crypto wallet add external commercial and payment channels unrelated to ad-copy generation. This is dangerous because it expands the attack surface for scams, off-platform solicitation, and unreviewed delivery of files or scripts through channels that bypass security review and user protections.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The invocation examples are broad and do not define clear trigger conditions, scope limits, or safety boundaries for when the skill should be used. This is risky because agents may invoke the skill opportunistically on loosely related prompts, exposing users to unwanted promotional content and increasing the chance of unintended tool behavior.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.