Back to skill

Security audit

Ads Audience Targeting

Security checks for vulnerabilities and agentic risk

Overview

This skill gives ad audience planning guidance and has broad marketing triggers, but it does not request tools, persistence, credentials, or direct account-changing authority.

Installers should treat this as an advisory marketing-planning skill. It may activate for broader ad strategy questions than audience segmentation, so review its recommendations before passing any handoff payload to tools or people that can modify real ad campaigns or budgets.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation criteria cover broad goals like growing revenue, improving ROAS, reducing CPA, and analyzing funnels, which extend well beyond the stated purpose of defining ICP segments and targeting hypotheses. This mismatch makes the skill more dangerous because it is execution-oriented and may be invoked for general ads strategy or campaign operations that should be handled by a different, more specialized skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger keywords are broad enough to match many generic business and marketing requests, which can cause this skill to activate outside its intended audience-segmentation scope. In an agent system, unintended invocation can route user requests to the wrong capability, producing unsafe or unauthorized operational ad guidance and increasing the chance of cascading downstream actions based on an incorrect skill selection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The available file only contains minimal metadata and does not include any implementation or descriptive detail supporting the broader manifest claim of building audience segmentation and targeting plans for Meta, Google Ads, TikTok, YouTube, and DSP campaigns. This creates a documentation-level mismatch between the stated scope and what is actually evidenced in the supplied skill file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.