Back to skill

Security audit

Ads Campaign Review

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only helper for advertising campaign retrospectives, with no code execution, credentials, persistence, or hidden data handling.

Safe to install as an advertising campaign review aid. Use it for ad retrospectives and manually review any budget, bidding, or strategy recommendation before applying it in live ad platforms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes very broad business terms such as "growth," "revenue," "profit," and "campaign," which are common across many non-advertising requests. This can cause unintended invocation of the skill in unrelated contexts, leading the agent to apply ad-analytics-specific logic where it does not belong and potentially produce misleading recommendations or route tasks incorrectly.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal