Back to skill

Security audit

ZuckerBot

Security checks across malware telemetry and agentic risk

Overview

This is a real Meta ads automation skill, but it can use stored credentials to launch or change paid campaigns without enough built-in approval and privacy guardrails.

Install only if you are comfortable connecting this integration to a Meta ads account. Before use, verify the external MCP package and ZuckerBot service, connect only the intended ad account, use the least permissions available, and require explicit human approval with the account, campaign, budget, destination URL, variant count, and conversion data before any launch, resume, bulk test, or conversion sync.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger criteria are excessively broad, instructing use whenever Meta/Facebook/Instagram advertising is mentioned in any context. In an agentic environment, this can cause the skill to activate for vague or informational requests and expose powerful ad-management actions without clear user intent, increasing the risk of unintended campaign changes or spend.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The workflows and tool descriptions include launch, pause, resume, and optimization actions that can spend money or alter live campaigns, but they do not require explicit user acknowledgment of financial and operational consequences. In this context, the skill is more dangerous because it is connected to live advertising infrastructure where a mistaken call can immediately incur budget spend or disrupt business operations.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The authentication section states that credentials are stored and used for subsequent calls, but it does not clearly warn that performance and conversion tools may transmit campaign metrics, business data, and conversion events to third parties via stored credentials. This creates consent and privacy risks because users may not realize ongoing actions can occur through persisted access tokens or API keys.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.