Back to skill

Security audit

ads

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent paid-ads guidance, but it claims live ad-account access and encourages customer-data uploads and lead-data reuse without enough confirmation, consent, or privacy guardrails.

Review before installing. Use this skill only where an operator will explicitly approve live campaign changes, budget moves, launches, pauses, audience uploads, and tracking changes. Do not upload customer lists, CRM exports, emails, phone numbers, or enriched identity data unless your organization has the required consent or lawful basis, honors opt-outs, and has checked platform and regional privacy rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill states it has direct access to ad platform accounts, which can prompt the agent to make or recommend live operational changes without explicitly warning the user about account impact or confirming intent. In the context of paid ads, budget, bidding, targeting, and launch changes can immediately spend money or alter production campaigns, so the missing guardrail is a real safety issue.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The eval explicitly rewards the skill for triggering on vague, casual phrasing ('we want to run retargeting ads...'), which can broaden activation beyond clearly scoped paid-ads requests. In an agent routing context, this increases the chance of over-triggering the ads skill on loosely related marketing conversations, causing misrouting, unnecessary tool use, or lower-quality responses when another skill would be more appropriate.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The playbook explicitly recommends taking CRM exports and identity-enriched audience data and uploading them to Meta for ad targeting, but it provides no guardrails around consent, lawful basis, platform custom-audience terms, or jurisdiction-specific privacy restrictions. In an ads operations skill, that omission is material because users may operationalize the workflow directly, creating privacy, compliance, and reputational risk through unauthorized use of personal data.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The guidance tells users to upload email lists for Customer Match and create similar audiences, but it omits any reminder that contact data is personal data and must only be used with appropriate consent, lawful basis, and platform-policy compliance. In an advertising skill, this omission can normalize privacy-unsafe behavior and lead to unauthorized use of customer PII in ad platforms.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The section advises uploading emails and phone numbers to build custom audiences without mentioning consent, notice, retention, hashing/secure transfer expectations, or restrictions on sensitive categories. Because this is operational how-to guidance, readers may directly act on it and mishandle personal data in ways that violate privacy law or platform rules.

Missing User Warnings

Low
Confidence
82% confidence
Finding
ABM guidance to upload target account lists is lower risk than direct consumer contact uploads, but it still can involve proprietary business data, employee identifiers, or account lists subject to contractual or confidentiality restrictions. The lack of any sensitivity or appropriate-use warning could encourage sharing data with ad platforms without internal approval or minimization.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The guide explicitly instructs implementers to send email and phone number data to Google Enhanced Conversions for ad attribution, but the surrounding section does not clearly require notice, consent, lawful basis validation, or minimization. Even if the SDK hashes the fields, this is still personal data processing and can create privacy, compliance, and trust risks if copied directly into production without proper governance.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The Meta CAPI section recommends server-side transmission of conversion events and parallel browser/server tracking, but it omits a strong warning that these events may include personal data and are subject to consent, disclosure, retention, and cross-border transfer requirements. In a how-to guide, that omission is risky because readers may implement broad server-side tracking assuming it is purely technical rather than regulated data processing.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The TikTok Advanced Matching example tells users to send email and phone number for attribution improvement without a clear warning in that section about privacy obligations. Hashing does not eliminate regulatory or security sensitivity, so the guidance could lead to non-compliant collection or sharing of personal data if adopted as-is.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The spec instructs the agent to switch to pt-BR for CFM-regulated Brazilian medical contexts without checking the user's requested language or offering a choice. This can cause unintended language coercion, reducing usability and potentially producing unsafe or noncompliant outputs if the user, operator, or downstream workflow expects another language.

Ssd 3

Medium
Confidence
95% confidence
Finding
The instruction to 'gather every identifier you can' encourages over-collection of audience data beyond what is necessary for the task. In an advertising skill, this can steer the agent to solicit, centralize, or infer sensitive customer attributes in plain language without minimization, purpose limitation, or consent checks, increasing privacy and compliance risk.

Ssd 3

Medium
Confidence
91% confidence
Finding
Telling users to call every non-converting lead and use their verbatim objections in ads risks collecting personal information during sales conversations and repurposing it for marketing without clear consent. Verbatim reuse can expose confidential or identifying details, and using customer statements in ad creative can create privacy, consent, and regulatory issues.

Ssd 3

Medium
Confidence
92% confidence
Finding
The repeated direction to call all leads who did not convert and reuse their verbatim answers reinforces a pattern of over-collection and secondary use of personal communications. Because this is framed as an operational growth tactic inside an ads skill, it increases the likelihood that private lead feedback will be captured and inserted into marketing materials without anonymization or consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.