Back to skill

Security audit

Ads Human Handoff

Security checks for vulnerabilities and agentic risk

Overview

This skill is not malicious, but it is marketed as human handoff while also directing the agent to give broad advertising, budget, and platform-action advice before escalation.

Install only if you want the agent to provide advertising triage and action suggestions as well as prepare handoffs. For high-spend, billing, account-lock, tracking, or policy issues, treat its recommendations as preliminary and require human review before changing budgets, bids, campaigns, or approvals.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The documented trigger scope expands far beyond human handoff coordination into general ad execution, growth, budgeting, and campaign strategy. That creates a capability mismatch: a skill presented as an escalation coordinator may instead intercept broad advertising requests and provide operational guidance, bypassing intended specialist review or safer routing boundaries.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger conditions are broad enough to match ordinary advertising conversations about growth, revenue, ROI, bidding, and channel strategy, not just genuine requests for human escalation. This increases the chance that the skill is invoked in the wrong context, where it may overreach into ad-operations guidance and crowd out more appropriate domain-specific or safety-constrained handling.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The output contract requires a direct answer, root-cause hypothesis, and immediate actions, which turns the skill into an advisory operator rather than a handoff coordinator. In practice, this can cause the agent to give concrete platform actions in situations that should be escalated, increasing the chance of unsafe spend changes, policy mistakes, or unsupported recommendations before a human reviews the case.

Static analysis

No suspicious patterns detected.